ToddyCat: your hidden email assistant. Part 1
ID: fed912a5-24c7-5d90-b2b5-e24be4a0cb7d
STIX ID: report--fed912a5-24c7-5d90-b2b5-e24be4a0cb7d
Feed Name: Securelist by Kaspersky
This Kaspersky report analyzes ToddyCat APT operations (mid‑2024–early‑2025) that evolved to exfiltrate corporate correspondence by: (1) using a PowerShell TomBerBil variant to copy browser data and DPAPI keys over SMB from domain hosts; (2) deploying TCSectorCopy to read locked Outlook OST files and exporting them with XstReader; and (3) dumping Microsoft 365 process memory (SharpTokenFinder/ProcDump) to capture OAuth JWT tokens. The report provides tool analyses, detection rules (audit/monitoring guidance, Sysmon/ProcDump detection), and IoCs (malicious binaries, file paths, PDB).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
