ToddyCat — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
November 24, 2025
Last Seen
July 17, 2026

Related Threat Clusters

Recent Intelligence Reports

  • GoSerpent Backdoor Looted Police and Biometric Data Across Southeast Asia for Five Years — Techtimes · July 17, 2026
  • ToddyCat APT uses remote debugging to hijack Gmail OAuth tokens — Feeds.4Sysops · July 2, 2026
  • ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts — Gbhackers · July 1, 2026
  • Longnosedgoblin Tries Sniff Out Governmental Affairs Southeast Asia Japan — www.welivesecurity.com · May 21, 2026
  • ToddyCat Malware Compromises Microsoft Exchange Servers using ProxyLogon Vulnerability — Cybersecuritynews · January 7, 2026
  • ToddyCat Malware Exploits ProxyLogon to Compromise Microsoft Exchange Servers — Gbhackers · January 7, 2026
  • ToddyCat revamps attack arsenal for email compromise — Scworld · November 26, 2025
  • ToddyCat APT evolves to target Outlook archives and Microsoft 365 tokens — Csoonline · November 26, 2025

CVSS v3.1 Breakdown