logo

Umbrij Malware Lets ToddyCat Hackers Hijack Gmail Accounts Through Google API Abuse

ID: 63518758-2957-5321-9ffb-31bbde8140f5

STIX ID: report--63518758-2957-5321-9ffb-31bbde8140f5

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-09

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

This report details a sophisticated ToddyCat APT-style campaign that distributes a malicious MSI masquerading as Kuailian/LetsVPN to deploy an Umbrij reflective loader and a feature-rich RAT; operators achieve stealthy, long-lived access, hijack Gmail by abusing Google APIs and OAuth tokens, implement persistence and anti-EDR checks, and use numerous C2 servers. The document includes technical analysis of the loader and payload, a list of IOCs (IPs, domains, file hashes), and recommended mitigations such as restricting Google API scopes and enforcing hardware MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.