logo

ToddyCat Malware Exploits ProxyLogon to Compromise Microsoft Exchange Servers

ID: b9f2cb14-78b7-5d63-a07e-f325688f3f4f

STIX ID: report--b9f2cb14-78b7-5d63-a07e-f325688f3f4f

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-07

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

ToddyCat (Websiic/Storm-0247) is a sophisticated APT operating since late 2020 that leverages Exchange server vulnerabilities (notably ProxyLogon CVE-2021-31207) and diverse malware (web shells, Samurai backdoor, Ninja Trojan, TCESB, TomBerBil) to harvest credentials, exfiltrate data (OST files via driver-level access), maintain persistence (scheduled tasks, reverse SSH tunnels), and evade detection using BYOVD and DLL sideloading; activity spans Europe, Asia, and Central Asia with active artifacts observed as recently as 2024 and recommended mitigations focusing on PowerShell monitoring, SMB access oversight, and network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.