HomeSecurityToddyCat targets Microsoft Exchange Servers via ProxyLogon

ToddyCat targets Microsoft Exchange Servers via ProxyLogon

The cyber espionage group ToddyCat has evolved in recent years into one of the most persistent and technically capable threat actors in the world. With targeted attacks on major organizations in Europe, Asia and Central Asia, its actions demonstrate that this is not an opportunistic group, but a long-term intelligence-gathering operation with a clear strategy.

ToddyCat ProxyLogon

ToddyCat's activity was first detected in December 2020, when the group managed to compromise Microsoft Exchange servers in Taiwan and Vietnam. What particularly concerned researchers was the use of an unknown vulnerability (zero-day), which indicated a high level of technical training and access to advanced exploits.

See also: Microsoft: Incorrect email routing enables internal domain phishing

This initial phase had a limited geographical scope, but it laid the foundation for a more aggressive and extensive course that would soon follow.

ProxyLogon: The turning point

In February 2021, ToddyCat made a significant leap forward by starting to exploit the ProxyLogon vulnerability in Exchange servers. This technique paved the way for mass attacks on organizations across Europe and Asia, transforming the group from a regional threat to a global player.

From that point on, ToddyCat's attack infrastructure is characterized by flexibility, tool switching, and the ability to quickly adapt to targets' defenses.

ToddyCat malware

For initial penetration and access maintenance, the team leveraged well-known but effective tools, such as the China Chopper web shells and the Samurai backdoor. These allowed them to gain solid footholds in compromised systems, maintaining a low profile and avoiding immediate detection.

See also: Chrome extensions have stolen conversations from ChatGPT and DeepSeek

By September 2021, their activity expanded to desktop systems in Central Asia, distributing Ninja Trojan loaders via Telegram, leveraging popular communication platforms to cover their tracks.

ToddyCat targets Microsoft Exchange Servers via ProxyLogon

New tools and an attack on security itself

2024 marked a new phase for ToddyCat, with the introduction of sophisticated tools like TCESB. These tools do not simply target operating systems, but attempt to exploit vulnerabilities in security products, directly undermining organizations' defenses.

Picus Security analysts point out that the team is particularly investing in persistence and continuous surveillance of targeted environments, using multiple execution methods to evade detection mechanisms.

Persistence and defense evasion in Windows

ToddyCat's persistence techniques demonstrate a deep understanding of architecture Windows security. The team creates scheduled tasks that execute automated PowerShell scripts with parameters that override execution policies. This allows malicious scripts, located in directories such as ProgramData, to be executed repeatedly without warning.

See also: Bug in Open WebUI turns 'free model' into a backdoor

Of particular concern is the use of the Bring Your Own Vulnerable Driver (BYOVD) technique, which involves installing the vulnerable DBUtilDrv2.sys driver. Through this, attackers can modify kernel structures, bypassing critical protections.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

ToddyCat targets Microsoft Exchange Servers via ProxyLogon

DLL side-loading and credential theft

At the same time, ToddyCat utilizes DLL side-loading, replacing legitimate libraries with malicious versions that execute code inside trusted processes. This method makes detection extremely difficult.

To collect credentials, the group dumps the memory of browsers such as Chrome, Firefox, and Edge, targeting files such as Login Data and logins.json. It also steals OAuth tokens from Microsoft 365 applications, gaining access to cloud resources.

A threat that shows no signs of tiring

All data is compressed and encrypted before being sent over command-and-control channels. This multi-layered approach explains why ToddyCat remains one of the most serious threats to modern businesses. In an environment where cyber espionage is becoming increasingly silent, ToddyCat proves that evolution is the attackers’ most powerful weapon.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS