Listen to this Post

Introduction
A sophisticated cyber-espionage operation is quietly targeting corporate networks worldwide. The notorious APT group ToddyCat has been refining its attack methods, combining browser credential theft, email exfiltration, and token hijacking to infiltrate organizations with unprecedented stealth. This campaign underscores the growing threat posed by advanced persistent threats leveraging both endpoint and cloud-based systems.
ToddyCat Powers Up: New TomBerBil PowerShell Variant
Between May and June 2024, researchers observed a new PowerShell variant of TomBerBil, the malware toolkit developed by ToddyCat. Unlike previous C and C++ versions that focused on collecting browser cookies and passwords, this updated script operates with elevated privileges on domain controllers and spreads via SMB shares to remote hosts. It creates local directories (e.g., C:\ProgramData emp), compiles host lists, and accesses administrative shares to extract sensitive browser data from Chrome, Edge, and Firefox.
Exfiltrating Browser Data
The malware targets files such as Login Data, Local State, Cookies, and History, along with DPAPI encryption keys stored in AppData\Microsoft\Protect. With these keys, attackers can decrypt browser-stored credentials offline, giving them access to multiple employee accounts. Detecting this activity involves monitoring SMB access paths and DPAPI directories, with Kaspersky-issued Sigma rules leveraging Windows Event IDs 5145 and 4663 to flag unauthorized access.
Shift to Outlook Data Theft
As local credential theft became more detectable, ToddyCat pivoted to stealing email content. The group deployed a C++ utility named TCSectorCopy to clone locked Outlook OST files through low-level sector reads. These files, containing cached Exchange or Microsoft 365 mailboxes, were then processed using XstReader, an open-source tool for converting mailbox data into readable formats.
Token Hijacking with SharpTokenFinder
ToddyCat also utilized SharpTokenFinder, a C tool that scans process memory for JWT tokens linked to Microsoft 365 applications like Outlook, Teams, and OneDrive. By combining this with Sysinternals’ ProcDump, attackers extracted OAuth tokens to access cloud mailboxes stealthily, bypassing conventional monitoring systems. Detection requires auditing ProcDump command-line arguments and monitoring Sysmon Event ID 9 for raw disk reads.
Advanced Espionage Tactics
This latest campaign illustrates ToddyCat’s escalation in espionage methods, blending traditional endpoint compromise with sophisticated cloud authentication attacks. The group’s ability to shift tactics and exploit both local and cloud environments makes detection increasingly complex for security teams.
What Undercode Say:
ToddyCat’s operations reflect a broader trend in APT evolution—attacks are no longer limited to single attack vectors but are increasingly hybrid. By combining browser credential theft with email exfiltration and cloud token hijacking, ToddyCat maximizes data exposure while minimizing the risk of detection.
From an analytical perspective, the use of DPAPI keys to decrypt browser credentials offline indicates a deep understanding of Windows security mechanisms. Meanwhile, the shift to OST file cloning and token extraction shows adaptive threat behavior, where attackers respond dynamically to defenses. Enterprises relying solely on endpoint protection are now insufficiently guarded; continuous auditing, behavior-based monitoring, and cloud token surveillance are essential for timely threat detection.
The tools employed—TomBerBil, TCSectorCopy, and SharpTokenFinder—demonstrate modularity and precision. Each component is highly specialized, reducing noise while maximizing the attack footprint. The operational sophistication signals a well-funded, organized group with persistent goals in corporate espionage, likely targeting high-value data rather than opportunistic theft.
Moreover, ToddyCat’s SMB-based lateral movement reveals the critical importance of controlling administrative shares and monitoring network activity for unusual access patterns. Even minor lapses in configuration can allow credential harvesting or token exfiltration to occur unnoticed. Organizations must therefore integrate cross-layered defense strategies that combine endpoint detection, network analytics, and cloud monitoring.
The campaign highlights the shifting landscape of cyber threats, where attackers exploit hybrid infrastructures—on-premise and cloud—simultaneously. This requires defenders to think beyond isolated systems, implementing holistic threat intelligence approaches that track activity across multiple platforms.
Strategically, understanding ToddyCat’s methods can inform predictive defense measures. For example, proactively monitoring DPAPI key access, unusual OST file interactions, and memory dump activity can prevent successful token hijacking. Threat hunting teams should consider these attack vectors as part of continuous security assessments.
The human factor remains a vulnerability; phishing, credential reuse, and misconfigured access can amplify ToddyCat’s success. Security teams should prioritize employee training, robust identity management, and multi-factor authentication to reduce the attack surface.
Finally, the emergence of PowerShell variants in malware highlights the evolving scripting threats, which bypass traditional signature-based defenses. Organizations must invest in script-blocking, code-signing validation, and anomaly detection tools to mitigate these sophisticated attacks.
Fact Checker Results:
✅ ToddyCat actively targets Microsoft 365 environments.
✅ New TomBerBil variant leverages PowerShell for elevated attacks.
❌ No evidence suggests widespread disruption beyond espionage; attacks remain stealth-focused.
Prediction:
📊 Expect ToddyCat to continue refining hybrid attack vectors, blending local credential theft with cloud token hijacking. Organizations relying solely on perimeter defenses will remain vulnerable. Increased investment in behavioral monitoring, AI-driven anomaly detection, and continuous cloud auditing will become critical in defending against advanced persistent threats like ToddyCat.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




