The cyber espionage group ToddyCat has evolved in recent years into one of the most persistent and technically capable threat actors in the world. With targeted attacks on major organizations in Europe, Asia and Central Asia, its actions demonstrate that this is not an opportunistic group, but a long-term intelligence-gathering operation with a clear strategy.

ToddyCat's activity was first detected in December 2020, when the group managed to compromise Microsoft Exchange servers in Taiwan and Vietnam. What particularly concerned researchers was the use of an unknown vulnerability (zero-day), which indicated a high level of technical training and access to advanced exploits.
See also: Microsoft: Incorrect email routing enables internal domain phishing
This initial phase had a limited geographical scope, but it laid the foundation for a more aggressive and extensive course that would soon follow.
ProxyLogon: The turning point
In February 2021, ToddyCat made a significant leap forward by starting to exploit the ProxyLogon vulnerability in Exchange servers. This technique paved the way for mass attacks on organizations across Europe and Asia, transforming the group from a regional threat to a global player.
From that point on, ToddyCat's attack infrastructure is characterized by flexibility, tool switching, and the ability to quickly adapt to targets' defenses.
ToddyCat malware
For initial penetration and access maintenance, the team leveraged well-known but effective tools, such as the China Chopper web shells and the Samurai backdoor. These allowed them to gain solid footholds in compromised systems, maintaining a low profile and avoiding immediate detection.
See also: Chrome extensions have stolen conversations from ChatGPT and DeepSeek
By September 2021, their activity expanded to desktop systems in Central Asia, distributing Ninja Trojan loaders via Telegram, leveraging popular communication platforms to cover their tracks.

New tools and an attack on security itself
2024 marked a new phase for ToddyCat, with the introduction of sophisticated tools like TCESB. These tools do not simply target operating systems, but attempt to exploit vulnerabilities in security products, directly undermining organizations' defenses.
Picus Security analysts point out that the team is particularly investing in persistence and continuous surveillance of targeted environments, using multiple execution methods to evade detection mechanisms.
Persistence and defense evasion in Windows
ToddyCat's persistence techniques demonstrate a deep understanding of architecture Windows security. The team creates scheduled tasks that execute automated PowerShell scripts with parameters that override execution policies. This allows malicious scripts, located in directories such as ProgramData, to be executed repeatedly without warning.
See also: Bug in Open WebUI turns 'free model' into a backdoor
Of particular concern is the use of the Bring Your Own Vulnerable Driver (BYOVD) technique, which involves installing the vulnerable DBUtilDrv2.sys driver. Through this, attackers can modify kernel structures, bypassing critical protections.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

DLL side-loading and credential theft
At the same time, ToddyCat utilizes DLL side-loading, replacing legitimate libraries with malicious versions that execute code inside trusted processes. This method makes detection extremely difficult.
To collect credentials, the group dumps the memory of browsers such as Chrome, Firefox, and Edge, targeting files such as Login Data and logins.json. It also steals OAuth tokens from Microsoft 365 applications, gaining access to cloud resources.
A threat that shows no signs of tiring
All data is compressed and encrypted before being sent over command-and-control channels. This multi-layered approach explains why ToddyCat remains one of the most serious threats to modern businesses. In an environment where cyber espionage is becoming increasingly silent, ToddyCat proves that evolution is the attackers’ most powerful weapon.
