ToddyCat Umbrij Malware Abuses Google OAuth
Score: 8/10

ToddyCat Umbrij Malware Abuses Google OAuth

The ToddyCat APT group utilizes Umbrij malware to compromise corporate Gmail accounts by leveraging a technique called Shadow Token via Remote Debug (STRD) to steal OAuth tokens.

Executive Summary

The ToddyCat APT group has introduced a specialized .NET malware named Umbrij, designed to automate the compromise of corporate Gmail accounts. By exploiting active sessions in Chromium-based browsers, the malware performs a technique known as 'Shadow Token via Remote Debug' (STRD). This allows the attackers to bypass multi-factor authentication and obtain persistent access to Google Workspace resources including Gmail, Drive, and Contacts.

The attack chain typically begins with a scheduled task that launches a legitimate, digitally signed executable. This executable is then leveraged to perform DLL side-loading of the obfuscated Umbrij payload. The malware focuses on corporate environments where users are likely to have authenticated Google sessions, specifically targeting migration tool IDs to gain broad permissions.

This development signifies a shift toward sophisticated browser automation for credential and token theft. Given ToddyCat's history of targeting government and military entities across Europe and Asia, organizations utilizing Google Workspace should prioritize monitoring for unauthorized browser debugging and anomalous OAuth application authorizations.

Key Details

Threat Name

Umbrij Malware

Affects

—

Adversary

ToddyCat

Malware/Tools

Umbrij, TCSectorCopy, TomBerBil, Ninja, Pcexter, Cobalt Strike, cuthead, HackTool:MSIL/Ninja, China Chopper, Samurai, EDRSandBlast, TCESB

Report Score

8out of 10
Quality Score
Good
IOC Quality7
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources