logo

ToddyCat: your hidden email assistant. Part 1

ID: fed912a5-24c7-5d90-b2b5-e24be4a0cb7d

STIX ID: report--fed912a5-24c7-5d90-b2b5-e24be4a0cb7d

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2025-11-21

Date Updated: 2026-04-29

Author: Andrey Gunkin

...
...

This Kaspersky report analyzes ToddyCat APT operations (mid‑2024–early‑2025) that evolved to exfiltrate corporate correspondence by: (1) using a PowerShell TomBerBil variant to copy browser data and DPAPI keys over SMB from domain hosts; (2) deploying TCSectorCopy to read locked Outlook OST files and exporting them with XstReader; and (3) dumping Microsoft 365 process memory (SharpTokenFinder/ProcDump) to capture OAuth JWT tokens. The report provides tool analyses, detection rules (audit/monitoring guidance, Sysmon/ProcDump detection), and IoCs (malicious binaries, file paths, PDB).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.