Back Feeds.4Sysops ToddyCat APT uses remote debugging to hijack Gmail OAuth tokens
The ToddyCat threat group is deploying a .NET-based malware called Umbrij that automates the compromise of corporate Gmail accounts without stealing passwords. The attack utilizes a technique known as Shadow Token via Remote Debug (STRD) to exploit active browser sessions on Windows hosts. Attackers gain initial access through DLL sideloading, often masquerading as legitimate components of Bitdefender, Visual Studio, or legacy Google software. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
