Scworld ToddyCat APT Enhances Techniques for Email Compromise
Article Content
Browse articles
The ToddyCat advanced persistent threat group has updated its methods to target Outlook emails and Microsoft 365 access tokens. Kaspersky Labs reported that between late 2024 and early 2025, ToddyCat refined its toolkit to capture email archives and access tokens, moving beyond previous tactics that focused on browser credentials.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track ToddyCat, TomBerBil and Outlook in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Spring Ring: Coordinated Vishing Campaign Exploits Microsoft Teams Between January and April 2026, a coordinated voice phishing campaign named Spring Ring targeted over 150 employees across more than 10 companies using fake IT support accounts on Microsoft Teams. Attackers registered external Teams tenants with names resembling internal IT departments to gain trust. The campaign…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…