ToddyCat Malware Exploits ProxyLogon to Compromise Microsoft Exchange Servers
ID: b9f2cb14-78b7-5d63-a07e-f325688f3f4f
STIX ID: report--b9f2cb14-78b7-5d63-a07e-f325688f3f4f
Feed Name: GBHackers
ToddyCat (Websiic/Storm-0247) is a sophisticated APT operating since late 2020 that leverages Exchange server vulnerabilities (notably ProxyLogon CVE-2021-31207) and diverse malware (web shells, Samurai backdoor, Ninja Trojan, TCESB, TomBerBil) to harvest credentials, exfiltrate data (OST files via driver-level access), maintain persistence (scheduled tasks, reverse SSH tunnels), and evade detection using BYOVD and DLL sideloading; activity spans Europe, Asia, and Central Asia with active artifacts observed as recently as 2024 and recommended mitigations focusing on PowerShell monitoring, SMB access oversight, and network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
