logo

ToddyCat is making holes in your infrastructure

ID: 1fdfbcbc-aa78-5167-a56f-d65c096c66b0

STIX ID: report--1fdfbcbc-aa78-5167-a56f-d65c096c66b0

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2024-04-22

Date Updated: 2026-04-29

Author: Andrey Gunkin, Alexander Fedotov, Natalya Shornikova

...
...

ToddyCat, an APT targeting Asia‑Pacific government and defense-related organizations, employs multiple tunneling and persistence mechanisms (reverse OpenSSH tunnels, SoftEther VPN, ngrok, FRP, DLL side‑loading) and bespoke/modified tools (cuthead for bulk document collection, WAExp for WhatsApp local storage, TomBerBil for browser credential/cookie extraction, Krong proxy) to harvest and exfiltrate large volumes of sensitive data; the report provides sample commands, filesystem paths, C2 hosts, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.