Executive Summary
The ToddyCat APT group has developed a specialized .NET tool named Umbrij to automate the compromise of corporate email hosted on Gmail. By leveraging a technique dubbed Shadow Token via Remote Debug (STRD), the group gains unauthorized access to user sessions without requiring victim interaction or credentials. The attack bypasses traditional EDR solutions by masquerading as legitimate processes and exploiting the OAuth 2.0 protocol via the Google API.
The attack chain begins with DLL sideloading using legitimate binaries from Bitdefender, Visual Studio, or Google Desktop. Once executed, Umbrij identifies active Chromium-based browser profiles, copies session-related data to a temporary directory, and launches a headless browser instance with remote debugging enabled. It then automates a series of permission requests to acquire an OAuth authorization code, which is subsequently exchanged for an access token to exfiltrate email and calendar data.
This activity represents a high risk to organizations using Google Workspace, as it effectively neutralizes the security benefits of active sessions and session-based authentication. The automation of these steps allows ToddyCat to scale their data collection efforts while maintaining a low forensic footprint on the host.
