Skip to content
ToddyCat APT uses remote debugging to hijack Gmail OAuth tokens

ToddyCat APT uses remote debugging to hijack Gmail OAuth tokens

Feeds.4Sysops •IT News • July 2, 2026

The ToddyCat threat group is deploying a .NET-based malware called Umbrij that automates the compromise of corporate Gmail accounts without stealing passwords. The attack utilizes a technique known as Shadow Token via Remote Debug (STRD) to exploit active browser sessions on Windows hosts. Attackers gain initial access through DLL sideloading, often masquerading as legitimate components of Bitdefender, Visual Studio, or legacy Google software. Source

Extracted Entities

APT Groups (1)

Attack Types (1)

Malware (1)

Platforms (2)

Tools (1)