news.mlab.sh
Back to the feed
threat-intel

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

High
Image: The Hacker News
Summary

The ToddyCat APT group is utilizing a new malware, Umbrij, to gain unauthorized access to Gmail accounts via the Google API. Umbrij leverages the OAuth 2.0 protocol to obtain access tokens, allowing attackers to control Chromium-based browsers and exfiltrate user data. This technique, dubbed STRD, involves launching the browser in headless mode and exploiting an active Gmail session to compromise accounts.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.