logo

ToddyCat: your hidden email assistant. Part 2

ID: 39cf12cc-02a0-5d18-bd6c-f5f387476c8a

STIX ID: report--39cf12cc-02a0-5d18-bd6c-f5f387476c8a

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2026-06-30

Date Updated: 2026-08-06

Author: Andrey Gunkin

...
...

**Executive summary:** This report analyzes ToddyCat APT's Umbrij, a .NET DLL used to stealthily obtain Google OAuth authorization codes from signed-in Chromium browser profiles by leveraging DLL sideloading, impersonating explorer.exe tokens, copying profile data, launching headless browsers with a remote debugging port, and automating account consent (the STRD technique). It documents multiple Umbrij variants, IoCs (hashes, vulnerable host binaries and paths), detection rules and mitigation steps such as monitoring DLL loads, detecting browsers launched with remote-debugging/headless flags, revoking unused third-party Google app access, and disabling developer tools for non‑developer hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.