Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

ToddyCat APT Unleashes Umbrij Malware to Compromise Corporate Gmail Communications via Google API

Cahyo Dewo, July 6, 2026

The sophisticated threat actor known as ToddyCat has once again demonstrated its evolving capabilities, with cybersecurity firm Kaspersky attributing to the group a new, insidious malware dubbed Umbrij. Designed with precision, Umbrij’s primary objective is to gain surreptitious and persistent access to a victim’s email correspondence, specifically targeting corporate communications hosted on Gmail through the exploitation of the Google API. This discovery, detailed in a comprehensive report published by Kaspersky this week, underscores the persistent and adapting nature of advanced persistent threat (APT) groups in their relentless pursuit of sensitive information and intelligence.

Unmasking Umbrij: A New Vector for Email Espionage

The focus of this particular campaign, as meticulously analyzed by Kaspersky, zeroes in on the critical realm of corporate email. Attackers have strategically aimed to compromise access via Google’s robust Application Programming Interfaces (APIs). The Google API, foundational to numerous integrated services and essential for modern cloud-based workflows, relies heavily on the OAuth 2.0 protocol for authorization. This protocol facilitates a secure delegation of access, allowing applications to use an OAuth token to access specific user resources, such as email, without ever needing the user’s direct password. It is precisely this mechanism that ToddyCat, through Umbrij, has sought to subvert and exploit.

Umbrij was developed with the explicit purpose of acquiring these highly sensitive OAuth tokens. Once a token is obtained, the malware leverages it to connect to a browser’s management console. Critically, this connection is established in ‘headless mode’ via a remote debugging port. Headless mode refers to running a browser environment without a graphical user interface, a common practice for automation, testing, or server-side rendering. However, in this malicious context, the remote debugging port, typically used by developers to inspect and control browser behavior, becomes the attacker’s clandestine gateway to manipulate the user’s active session.

Following this initial unauthorized connection, Umbrij orchestrates a series of intricate requests designed to obtain an OAuth authorization code. This code is then meticulously exchanged for an access token, which subsequently grants the attackers the coveted ability to reach and manipulate target resources via the API. Kaspersky has aptly codenamed this sophisticated technique "Shadow Token via Remote Debug" (STRD), a moniker that effectively captures the clandestine nature of the operation and its reliance on hidden browser functionalities. The STRD technique is particularly concerning because it bypasses traditional credential theft, instead focusing on hijacking existing, legitimate sessions.

What distinguishes the STRD attack is its operational viability on widely used Chromium-based browsers, such as Google Chrome and Microsoft Edge, and its exploitation of an active Gmail session. This means the attackers do not need to phish credentials or bypass multi-factor authentication (MFA) in the traditional sense. Instead, the strategy hinges on launching the compromised browser in headless mode, establishing control through the remote debugging port, and then leveraging an already logged-in Gmail session. By doing so, the malware effectively "hijacks" the legitimate session to obtain access to the Google account’s resources, rendering the attack remarkably stealthy and difficult to detect through conventional means that focus solely on login attempts.

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

Kaspersky’s investigation has revealed the existence of at least three distinct versions of Umbrij, indicating ongoing development and refinement by the ToddyCat group. These variants include helper functions that demonstrate the attackers’ meticulous attention to detail, such as capabilities for debugging and for efficiently searching and selecting specific user accounts within the compromised browser environment. This modularity suggests an adaptable toolkit, capable of being tailored for different targets or operational requirements, allowing for greater precision and efficiency in their cyberespionage operations.

ToddyCat’s Persistent Pursuit: A History of Email Targets

The attribution of Umbrij to ToddyCat is not an isolated event but rather a continuation of a well-established pattern of sophisticated cyberespionage activities. ToddyCat is the designation assigned to a highly organized and advanced persistent threat (APT) group that has been active since at least 2020. Throughout its operational history, the group has consistently targeted a diverse array of organizations across Europe and Asia, focusing on sectors rich in sensitive data, including government agencies, defense contractors, research institutions, and critical infrastructure providers. Their long-term objectives typically involve intelligence gathering, intellectual property theft, and data exfiltration, making email communications a prime target due to the wealth of strategic and proprietary information they invariably contain.

A notable precursor to the Umbrij campaign was detailed by Kaspersky in November 2025. In that instance, the cybersecurity firm exposed ToddyCat’s use of a custom-built tool named TCSectorCopy. This malware was specifically engineered to exfiltrate Microsoft Outlook email data from targeted companies. The recurring theme of targeting email systems, whether Gmail or Outlook, underscores ToddyCat’s strategic emphasis on gaining access to internal communications, which often hold invaluable intelligence, intellectual property, or strategic insights. This pattern reinforces the notion that corporate email remains a high-value asset for nation-state-backed (or similarly resourced) APT groups, who are willing to invest significant resources into developing bespoke tools for compromise.

The discovery of Umbrij emerged from a diligent "threat hunting operation" conducted by Kaspersky’s security researchers. This proactive approach to cybersecurity involves continuously searching for new and unknown threats within networks, moving beyond signature-based detection. During this operation, Kaspersky identified a suspicious scheduled task masquerading as legitimate software from their own suite, specifically "KasperskyEndpointSecurityEDRAvp." This seemingly innocuous scheduled task was, in fact, the initial vector, designed to launch a digitally signed file. This signed file then employed a technique known as DLL side-loading to inject and execute the malicious Umbrij payload.

The Mechanics of Compromise: DLL Side-Loading and System Entrenchment

DLL side-loading is a prevalent and effective evasion technique used by threat actors, particularly APT groups, due to its ability to leverage trusted processes. It exploits the legitimate way Windows applications load Dynamic Link Libraries (DLLs). When an application starts, it searches for necessary DLLs in a predefined order of directories. If an attacker can place a malicious DLL with the same name as a legitimate one in an earlier search path, the application will load the malicious DLL instead of the intended one, thereby executing the attacker’s code. This method is particularly potent because it abuses legitimate software, often digitally signed, to bypass security controls, elevate privileges, and establish a persistent foothold on a compromised system.

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

In the case of Umbrij, Kaspersky identified that one of three legitimate binaries, known to be susceptible to DLL side-loading, was abused. While the specific binaries were not enumerated in the initial report, the principle remains consistent: a legitimate, trusted executable unwittingly loads and executes the malicious Umbrij DLL. The Umbrij DLL itself is written in .NET and further obfuscated using ConfuserEx, an open-source obfuscator. Obfuscation techniques like ConfuserEx are employed to make the malware’s code difficult for security researchers to analyze and reverse-engineer, thereby hindering detection and understanding of its full capabilities, buying the attackers more time before defensive measures can be developed.

The tool can also be invoked with various command-line parameters, granting the attackers granular control over its operation. These parameters allow specifying which Chromium-based browsers to target (Google Chrome or Microsoft Edge), instructing the malware to save a screenshot of the user profile as a PDF file (a valuable intelligence-gathering feature to understand the user’s environment), and even providing the system username under which the tool will execute, allowing for targeted exploitation within a multi-user environment.

Upon successful launch, Umbrij initiates a multi-stage sequence of preparatory actions on the compromised Windows host to effectively breach the Gmail account. This intricate workflow, demonstrating significant technical prowess, includes:

  1. System Configuration Checks: Verifying the operating environment to ensure optimal execution and avoid detection by sandboxes or virtualized analysis environments.
  2. Browser Profile Identification: Locating the active profiles for targeted Chromium browsers (Chrome or Edge), as these profiles contain the session cookies and other data necessary for the attack.
  3. Registry Modifications: Adjusting specific system registry settings to facilitate headless browser operation and enable remote debugging functionality, often by temporarily relaxing security policies.
  4. Process Manipulation: Launching the browser process in headless mode, carefully configured to open a specific Google authentication URL or a URL that triggers the OAuth flow.
  5. Establishing Debugging Connection: Connecting to the browser’s remote debugging port, effectively taking full control of the browser session without the user’s knowledge or interaction.
  6. Session Hijacking: Leveraging the active, legitimate Gmail session to interact with Google’s authentication mechanisms, thereby appearing as a legitimate user.
  7. OAuth Code Acquisition: Intercepting and extracting the OAuth authorization code generated during the process, which is a temporary credential.
  8. Data Exfiltration Preparation: Preparing the retrieved authorization code for subsequent exfiltration from the compromised host to the attacker’s command-and-control infrastructure.
  9. Logging: Meticulously logging all its actions and the retrieved authorization code to a file for later retrieval by the attackers, providing a detailed record of the compromise.

This detailed sequence highlights the advanced technical sophistication of ToddyCat, showcasing their ability to integrate various techniques – from initial access to stealthy data exfiltration – into a cohesive and highly effective attack chain, specifically tailored for API-based account compromise.

The Strategic Value of OAuth Tokens and Broader Implications

The strategy behind Umbrij underscores the growing importance of API security in the modern digital landscape. As applications and services increasingly rely on APIs for interconnectivity and functionality, these interfaces become attractive and often overlooked targets for cybercriminals and state-sponsored actors. The OAuth 2.0 protocol, while a widely adopted standard for secure delegation, presents a vulnerability if its tokens or the mechanisms to acquire them can be compromised. An OAuth access token acts as a digital key, granting specific permissions to a user’s data without needing their password. If this key is stolen, attackers gain direct access to the associated resources, bypassing traditional authentication layers and potentially multi-factor authentication.

Kaspersky’s analysis confirmed that "Umbrij, like most other tools in ToddyCat’s arsenal, logs its actions in detail and saves them to a file." This meticulous logging is not merely for operational tracking but also serves a critical function: "It also saves the retrieved authorization code to this log file, which the operator subsequently exfiltrates from the compromised host." This exfiltrated authorization code is then exchanged for an OAuth access token, which is the ultimate prize. With this token in hand, the threat actors can connect to the Gmail account directly through the API, gaining unauthorized access to corporate email communications. This could include reading emails, sending messages, accessing contacts, downloading attachments, and even manipulating settings, depending on the scope of the token and the permissions granted to the legitimate application it mimics.

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

The implications of such an attack are far-reaching and potentially catastrophic for targeted organizations. For corporate entities, the compromise of email communications can lead to:

  • Intellectual Property Theft: Exfiltration of sensitive business plans, research data, product designs, and proprietary algorithms exchanged via email.
  • Espionage and Competitive Intelligence: Gaining insights into strategic decisions, merger and acquisition plans, competitive intelligence, or government policies.
  • Supply Chain Compromise: Using compromised email accounts to launch further, highly credible spear-phishing or business email compromise (BEC) attacks against partners, customers, or critical suppliers.
  • Reputational Damage: The public disclosure of compromised communications can severely damage an organization’s standing, customer trust, and market value.
  • Financial Loss: Direct financial theft or manipulation through sophisticated business email compromise (BEC) scams initiated from trusted, compromised accounts, rerouting payments or tricking employees.
  • Regulatory Fines and Legal Ramifications: Data breaches involving personal or sensitive corporate information can incur significant fines under data protection regulations like GDPR or CCPA, alongside potential lawsuits.

Official Responses and Mitigation Strategies

Andrey Gunkin, a senior malware analyst at Kaspersky, reiterated the gravity of the situation, stating, "The ToddyCat APT group continues to search for ways of compromising corporate email communications. Their new tool, Umbrij, automates the attackers’ attempts to gain access to organizational email accounts. This automation not only helps increase the scale and frequency of their attacks but also demonstrates ToddyCat’s strong motivation and advanced technical skills." This statement highlights the group’s relentless focus on email as a high-value target and their continuous investment in sophisticated tooling to achieve their intelligence-gathering objectives.

While Google was not directly quoted in the original report regarding this specific threat, their public stance on security consistently emphasizes shared responsibility and robust protection mechanisms for their platforms and users. Google continuously works to secure its APIs and the OAuth protocol through various security enhancements and monitoring. However, attacks like Umbrij demonstrate that endpoint security, user vigilance, and proactive management of application permissions remain paramount. Google provides users with accessible tools to manage and review third-party application access, a critical defense against token misuse.

To counter the threat posed by Umbrij and similar token-based attacks, cybersecurity experts and industry best practices advise several crucial steps for both organizations and individual users:

  1. Regularly Review Application Permissions: Organizations and individual users are strongly advised to regularly review the authorization codes and permissions granted to third-party applications. This can be done by navigating to "myaccount.google[.]com/connections" for Google accounts.
  2. Identify Suspicious Applications: Within the connections list, users should specifically look for applications named "Google Workspace Migration for Microsoft Outlook" or "Google Workspace Sync for Microsoft Outlook." While these are legitimate Google applications, their presence might be suspicious if they are not genuinely used within the organization, indicating a potential impersonation or unauthorized installation.
  3. Revoke Unauthorized Access Immediately: If either of these applications, or any other unfamiliar or unused application, is present and not legitimately employed within the organization, it is absolutely essential to revoke their access immediately. Revoking access invalidates any associated OAuth tokens, effectively cutting off the attacker’s unauthorized entry point and preventing further access.
  4. Implement Robust Endpoint Security: Deploying advanced endpoint detection and response (EDR) solutions can help detect anomalous activities like DLL side-loading, the launch of headless browsers for suspicious purposes, and attempts to connect to remote debugging ports, providing an early warning system.
  5. Enforce Multi-Factor Authentication (MFA): While Umbrij leverages an active session, strong MFA can prevent initial compromises that lead to persistent active sessions and can alert users to unusual login attempts if a token is eventually used on a new device or from a new location.
  6. Comprehensive Security Awareness Training: Educating employees about the dangers of phishing, suspicious downloads, the importance of reviewing application permissions, and reporting unusual system behavior is vital to create a human firewall against such sophisticated attacks.
  7. Regular Audits and Patch Management: Keeping operating systems, browsers, and all security software up to date with the latest patches and conducting regular security audits can significantly reduce the attack surface and close known vulnerabilities that APT groups often exploit.
  8. Network Segmentation and Least Privilege: Implementing network segmentation can limit lateral movement, and applying the principle of least privilege ensures that even if an account is compromised, the attacker’s access to critical resources is minimized.

The emergence of Umbrij serves as a stark reminder that the cybersecurity landscape is in a constant state of flux, with APT groups continually innovating their tactics, techniques, and procedures (TTPs). The shift towards targeting API authorization flows and leveraging legitimate browser functionalities in unexpected ways highlights a significant evolution in cyberespionage. As organizations increasingly adopt cloud-based services like Gmail, the security of the underlying APIs and the endpoints accessing them becomes an even more critical component of a comprehensive cybersecurity strategy. The ongoing cat-and-mouse game between threat actors and defenders necessitates continuous vigilance, advanced threat intelligence, and proactive security measures to safeguard sensitive corporate communications from sophisticated adversaries like ToddyCat.

Cybersecurity & Digital Privacy communicationscompromisecorporateCybercrimegmailgoogleHackingmalwarePrivacySecuritytoddycatumbrijunleashes

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes