Executive Summary
The ToddyCat APT group has introduced a specialized .NET malware named Umbrij, designed to automate the compromise of corporate Gmail accounts. By exploiting active sessions in Chromium-based browsers, the malware performs a technique known as 'Shadow Token via Remote Debug' (STRD). This allows the attackers to bypass multi-factor authentication and obtain persistent access to Google Workspace resources including Gmail, Drive, and Contacts.
The attack chain typically begins with a scheduled task that launches a legitimate, digitally signed executable. This executable is then leveraged to perform DLL side-loading of the obfuscated Umbrij payload. The malware focuses on corporate environments where users are likely to have authenticated Google sessions, specifically targeting migration tool IDs to gain broad permissions.
This development signifies a shift toward sophisticated browser automation for credential and token theft. Given ToddyCat's history of targeting government and military entities across Europe and Asia, organizations utilizing Google Workspace should prioritize monitoring for unauthorized browser debugging and anomalous OAuth application authorizations.
Key Details
Threat Name
Umbrij Malware
Affects
—
Adversary
ToddyCat
MITRE Techniques
Malware/Tools
Umbrij, TCSectorCopy, TomBerBil, Ninja, Pcexter, Cobalt Strike, cuthead, HackTool:MSIL/Ninja, China Chopper, Samurai, EDRSandBlast, TCESB
