ToddyCat: your hidden email assistant. Part 2
ID: 39cf12cc-02a0-5d18-bd6c-f5f387476c8a
STIX ID: report--39cf12cc-02a0-5d18-bd6c-f5f387476c8a
Feed Name: Securelist by Kaspersky
**Executive summary:** This report analyzes ToddyCat APT's Umbrij, a .NET DLL used to stealthily obtain Google OAuth authorization codes from signed-in Chromium browser profiles by leveraging DLL sideloading, impersonating explorer.exe tokens, copying profile data, launching headless browsers with a remote debugging port, and automating account consent (the STRD technique). It documents multiple Umbrij variants, IoCs (hashes, vulnerable host binaries and paths), detection rules and mitigation steps such as monitoring DLL loads, detecting browsers launched with remote-debugging/headless flags, revoking unused third-party Google app access, and disabling developer tools for non‑developer hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
