news.mlab.sh
Threat intelligence
Threat actor

ToddyCat

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2020-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Defense, Government, Telecommunications
TLP
WHITE

(Kaspersky) ToddyCat is a relatively new APT actor that we have not been able to relate to other known actors, responsible for multiple sets of attacks detected since December 2020 against high-profile entities in Europe and Asia. We still have little information about this actor, but we know that its main distinctive signs are two formerly unknown tools that we call ‘Samurai backdoor’ and ‘Ninja Trojan’.

Also known as

Storm-0247ToddyCat

Vulnerabilities exploited

Tooling and malware

China ChopperCobalt StrikeLoFiSeNinjaPcexterSamuraiNetnetstatPing

MITRE ATT&CK techniques

T1005 Data from Local SystemT1095 Non-Application Layer ProtocolT1686 Disable or Modify System FirewallT1018 Remote System DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1083 File and Directory DiscoveryT1680 Local Storage DiscoveryT1047 Windows Management InstrumentationT1106 Native APIT1190 Exploit Public-Facing Application

Coverage 2