ToddyCat APT Is Stealing Data on 'Industrial Scale'
ID: c0e1bb30-6b39-551b-80b0-858500764667
STIX ID: report--c0e1bb30-6b39-551b-80b0-858500764667
Feed Name: Dark Reading
Kaspersky researchers attribute a sustained data‑collection campaign to the ToddyCat APT targeting government and defense organizations across the Asia‑Pacific region since at least 2020. The actor maintains persistence via multiple simultaneous access tunnels (reverse SSH, SoftEther VPN, Ngrok, fast reverse proxy) and uses newly observed tools — Cuthead (file collection), WAExp (WhatsApp Web local storage harvesting), and TomBerBil (Chrome/Edge password theft) — alongside known web shells; defenders are advised to block cloud tunneling service IPs, restrict remote access tools, and avoid storing credentials in browsers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
