ToddyCat is making holes in your infrastructure
ID: 1fdfbcbc-aa78-5167-a56f-d65c096c66b0
STIX ID: report--1fdfbcbc-aa78-5167-a56f-d65c096c66b0
Feed Name: Securelist by Kaspersky
Date Published: 2024-04-22
Date Updated: 2026-04-29
Author: Andrey Gunkin, Alexander Fedotov, Natalya Shornikova
ToddyCat, an APT targeting Asia‑Pacific government and defense-related organizations, employs multiple tunneling and persistence mechanisms (reverse OpenSSH tunnels, SoftEther VPN, ngrok, FRP, DLL side‑loading) and bespoke/modified tools (cuthead for bulk document collection, WAExp for WhatsApp local storage, TomBerBil for browser credential/cookie extraction, Krong proxy) to harvest and exfiltrate large volumes of sensitive data; the report provides sample commands, filesystem paths, C2 hosts, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
