Umbrij Malware Lets ToddyCat Hackers Hijack Gmail Accounts Through Google API Abuse
ID: 63518758-2957-5321-9ffb-31bbde8140f5
STIX ID: report--63518758-2957-5321-9ffb-31bbde8140f5
Feed Name: GBHackers
This report details a sophisticated ToddyCat APT-style campaign that distributes a malicious MSI masquerading as Kuailian/LetsVPN to deploy an Umbrij reflective loader and a feature-rich RAT; operators achieve stealthy, long-lived access, hijack Gmail by abusing Google APIs and OAuth tokens, implement persistence and anti-EDR checks, and use numerous C2 servers. The document includes technical analysis of the loader and payload, a list of IOCs (IPs, domains, file hashes), and recommended mitigations such as restricting Google API scopes and enforcing hardware MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
