ToddyCat is a China-affiliated advanced persistent threat actor focused on cyberespionage and long-term access to organizational networks and cloud accounts. Also tracked as Storm-0247 and Websiic, it targets government bodies and private organizations, including information technology, telecommunications, and engineering companies, particularly in Asia and Europe. Websiic activity included exploitation of Microsoft Exchange ProxyLogon vulnerabilities before patches were released in March 2021. ToddyCat gains initial access through exploitation of server vulnerabilities and distribution of malicious loaders through messaging applications. Its post-compromise tradecraft includes custom remote-access tools, PowerShell, DLL side-loading, malicious Windows services, and remote scheduled tasks. Operators transfer tools between hosts over SMB, use domain credentials for remote execution, and download additional collection and archiving utilities. The group conducts security-software discovery, conceals PowerShell execution, and masquerades malware as legitimate software. Collected data is compressed and exfiltrated using tools such as SIMPOBOXSPY and Dropbox uploaders. ToddyCat also uses Umbrij to implement Shadow Token via Remote Debug (STRD), a persistence technique targeting Google Workspace. Umbrij duplicates an authenticated Chrome or Edge profile and launches a headless browser with remote debugging enabled. Using Puppeteer and the DevTools protocol, it silently completes an OAuth consent flow while impersonating legitimate Google Workspace migration or synchronization applications. The resulting authorization code is transferred to attacker infrastructure and exchanged for an OAuth access token. This enables direct access to mailboxes and other authorized resources without continued endpoint access; persistence after password changes depends on Workspace configuration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
16 CVEs this actor has used in observed campaigns. 16 of them exploited in the wild.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
11 more CVEs tied to this actor tracked in Mallory.
135 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only in technique annotations. The content does not attribute ResetNightmare exploitation or a specific campaign to this group.
Referenced only as an annotated actor associated with the detection technique.
Previously abused ESET software for DLL side-loading by exploiting a search-order flaw in ESET's command-line scanner.
Listed in the detection's Annotations section.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.