ToddyCat Hacker Group Uses Advanced Tools for Industrial-Scale Data Theft
ID: 52364de1-f806-55ac-bd35-36b3b13dbf69
STIX ID: report--52364de1-f806-55ac-bd35-36b3b13dbf69
Feed Name: The Hacker News
ToddyCat is an APT targeting government and military entities in the Asia‑Pacific that uses a wide range of backdoors, exfiltration tools (LoFiSe, Pcexter), tunneling solutions (reverse SSH/OpenSSH, SoftEther, Ngrok, Krong, FRP) and credential/cookie stealers (TomBerBil, WAExp) to automate industrial‑scale data harvesting and maintain redundant persistent access; Kaspersky documents active use and recommends blocking tunneling cloud services and preventing browser‑stored passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
