216.73.216.6

New Tools and Techniques of ToddyCat APT

· Published 21/11/2025 14:38 · Modified 21/11/2025 22:35

Export JSON

Essential information

Published
21/11/2025 14:38
Modified
21/11/2025 22:35
Tags
2025-11-21 apt browser data theft email oauth outlook powershell sharptokenfinder tcsectorcopy tomberbil xstreader
Related entities
1 intrusion sets (apt), 3 techniques (mitre)

Description

The ToddyCat group has evolved its methods to gain covert access to corporate . The report details their use of -based for extracting data, for copying OST files, and attempts to steal tokens from Microsoft 365 processes. These tools allow the attackers to bypass security monitoring and access data both on-premises and in the cloud. The group's tactics include using SMB to remotely access files, dumping process memory, and searching for access tokens. Detection recommendations are provided for each technique.

External references