ToddyCat APT Umbrij Tool and OAuth Token Theft
Score: 9/10

ToddyCat APT Umbrij Tool and OAuth Token Theft

ToddyCat APT uses the Umbrij tool to automate OAuth token theft from Chromium-based browsers via remote debugging ports to access victim Gmail accounts.

Executive Summary

The ToddyCat APT group has developed a specialized .NET tool named Umbrij to automate the compromise of corporate email hosted on Gmail. By leveraging a technique dubbed Shadow Token via Remote Debug (STRD), the group gains unauthorized access to user sessions without requiring victim interaction or credentials. The attack bypasses traditional EDR solutions by masquerading as legitimate processes and exploiting the OAuth 2.0 protocol via the Google API.

The attack chain begins with DLL sideloading using legitimate binaries from Bitdefender, Visual Studio, or Google Desktop. Once executed, Umbrij identifies active Chromium-based browser profiles, copies session-related data to a temporary directory, and launches a headless browser instance with remote debugging enabled. It then automates a series of permission requests to acquire an OAuth authorization code, which is subsequently exchanged for an access token to exfiltrate email and calendar data.

This activity represents a high risk to organizations using Google Workspace, as it effectively neutralizes the security benefits of active sessions and session-based authentication. The automation of these steps allows ToddyCat to scale their data collection efforts while maintaining a low forensic footprint on the host.

Key Details

Threat Name

ToddyCat Umbrij Tool

Affects

—

Adversary

ToddyCat

Malware/Tools

Umbrij, TomBerBil

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance9
Enterprise Relevance10
Clarity & Structure10
Technical Depth9

Sources