threat-intel
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
High
Summary
The ToddyCat APT group is utilizing a new malware, Umbrij, to gain unauthorized access to Gmail accounts via the Google API. Umbrij leverages the OAuth 2.0 protocol to obtain access tokens, allowing attackers to control Chromium-based browsers and exfiltrate user data. This technique, dubbed STRD, involves launching the browser in headless mode and exploiting an active Gmail session to compromise accounts.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
