logo

ToddyCat APT Umbrij Tool Steals Cloud Email Tokens

ID: d12632d7-a33a-5a3b-8d1b-f7811da2c104

STIX ID: report--d12632d7-a33a-5a3b-8d1b-f7811da2c104

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-07-03

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

The report documents a suspected ToddyCat APT campaign using a tool called Umbrij to steal OAuth authorization codes from Chromium-based Gmail sessions by abusing DLL sideloading and remote debugging (via Puppeteer) to run headless browsers and exchange authorization codes for access tokens, enabling full access to corporate email, Drive and contacts while evading typical security monitoring; Kaspersky and private researchers tracked multiple variants and recommend monitoring for remote debugging activity, unusual headless browser launches, OAuth application auditing, and DLL sideloading detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.