threat-intel
ToddyCat: your hidden email assistant. Part 2
High
Summary
This report details the tactics employed by the ToddyCat APT group, focusing on a new technique dubbed ‘Shadow Token via Remote Debug’ (STRD) to compromise Gmail accounts. The group utilized a tool named Umbrij to gain access to user sessions via the Google API, exploiting active browser sessions and OAuth 2.0 authorization. This attack leverages DLL sideloading through legitimate Windows applications to deploy the malicious Umbrij tool, highlighting the importance of monitoring for suspicious process execution and unauthorized DLL loading.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
