news.mlab.sh
1 result
threat-intel

ToddyCat: your hidden email assistant. Part 2

This report details the tactics employed by the ToddyCat APT group, focusing on a new technique dubbed ‘Shadow Token via Remote Debug’ (STRD) to compromise Gmail accounts. The group utilized a tool named Umbrij to gain access to user sessions via the Google API, exploiting active browser sessions and OAuth 2.0 authoriz…

Securelist · Jun 30, 2026 High