HomeSecurityToddyCat: New Umbrij malware targets corporate Gmail accounts

ToddyCat: New Umbrij malware targets corporate Gmail accounts

Kaspersky researchers have uncovered a new cyberespionage campaign attributed to the advanced threat group (APT) ToddyCat , which leverages a previously unknown malware called Umbrij . The tool is designed to gain covert access to corporate Gmail accounts by exploiting the Google API and OAuth authorization mechanisms .

Article Image: ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

According to detailed report , attackers are now focusing on corporate communications via Gmail, seeking to gain access to email data without requiring the interception of passwords or breaching Google's security systems.

Target OAuth tokens instead of passwords

The new technique differs significantly from classic phishing or credential theft attacks. Instead of attempting to steal a username and password, Umbrij aims to obtain a valid OAuth token, which allows access to account resources via the Google API.

OAuth is a widely used authorization mechanism that allows third-party applications to access specific data in a Google account without needing to know the user's actual password. However, if such a token falls into the wrong hands, cybercriminals can gain access to a large portion of the account's information.

How Umbrij works

As Kaspersky analysts explain, Umbrij leverages a highly sophisticated process that exploits active Gmail sessions within Chromium -based browsers , such as Google Chrome and Microsoft Edge.

Initially, the malware launches the browser in headless, i.e. without displaying the graphical interface to the user. It then connects to a Remote Debugging Port, essentially gaining control of the active browser session.

From there, the tool starts a sequence of automated actions that lead to the acquisition of an OAuth authorization code, which is later exchanged for an access token. This token is used to access Gmail accounts through the official Google API.

Kaspersky named this particular technique Shadow Token via Remote Debug (STRD), as it is based on abusing an already active user session without requiring a new login process.

See also: ToddyCat targets Microsoft Exchange Servers via ProxyLogon

Why is the attack considered particularly dangerous?

What makes the technique so effective is that it leverages an already authenticated Gmail session. As long as the user is logged into their account via Chrome or Edge, Umbrij can exploit active cookies and stored credentials, bypassing much of the traditional protection mechanisms.

In this way, the perpetrators gain access not only to emails, but also to any Google service for which the corresponding permission has been granted via OAuth.

This technique makes it even more difficult to detect the attack, as access is made through legitimate Google APIs and not through suspicious connections or unauthorized logins.

Multiple versions of malware

While analyzing the campaign, researchers identified three different versions of Umbrij. Each has different capabilities, such as debugging mechanisms, functions to detect Google accounts stored in the browser, and tools to select the profile to target.

The existence of multiple versions shows that the malware is constantly evolving and adapting to the needs of the group's attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

ToddyCat: New Umbrij malware targets corporate Gmail accounts

ToddyCat continues to evolve its arsenal

ToddyCat is one of the most sophisticated cyber espionage groups operating in recent years. According to Kaspersky, the group has been carrying out targeted attacks against organizations in Europe and Asia since at least 2020, constantly using new tools and techniques.

This is not the first time the group has targeted corporate email systems. In November 2025, researchers uncovered the TCSectorCopy, which was used to extract data from corporate Microsoft Outlook.

The emergence of Umbrij indicates that ToddyCat is now expanding its reach to Google services, leveraging new techniques that rely on legitimate operating system and browser features. This choice makes it significantly more difficult to detect the activity, as much of the attack is carried out using normal processes and official tools, rather than overtly malicious software.

How the new campaign was discovered

Kaspersky uncovered Umbrij during a targeted threat hunting operation, where analysts spotted suspicious activity on compromised corporate systems. The investigation found that the attackers were using a Scheduled Task, which appeared as a legitimate process with a name that referred to Kaspersky's own security software.

The goal of this technique was to not raise suspicions among system administrators or monitoring tools, as the execution of the malware appeared to come from a completely normal security service.

See also: APT group ToddyCat gains access to internal employee communications

The DLL side-loading technique

Researchers also found that Umbrij exploits the well-known DLL side-loading, through which legitimate executable files load malicious DLL libraries instead of the authentic ones.

The ToddyCat campaign exploited three different legitimate programs that are vulnerable to this method. These include Bitdefender ConnectAgent's BDSubWiz.exe , Microsoft Visual Studio's VSTestVideoRecorder.exe , and the older GoogleDesktop.exe , which came from the now-deprecated Google Desktop Search application.

Regardless of which executable file is used, the result remains the same: loading the malicious DLL containing Umbrij.

The malware itself is developed in .NET and its code has been obfuscated with the ConfuserEx tool, a technique that significantly complicates its analysis and detection by security software.

ToddyCat: New Umbrij malware targets corporate Gmail accounts

Preparing the attack

Immediately after its execution, Umbrij performs a series of actions in order to collect all the necessary information from the victim's computer.

It first checks if the port to be used for Remote Debugging of the browser is available. It then obtains the rights of the logged-in user by copying the security token of the explorer.exe, ensuring that it will operate with the same rights as the system user.

It then searches Google Chrome and Microsoft Edge profiles, parsing the configuration files to locate saved Google accounts. The presence of a Gmail address is an indication that the user is already logged in to Google services and therefore there is an active session that can be exploited.

Copying browser data

In the next stage, the malware creates a temporary backup directory inside the Chrome or Edge folders.

There it copies critical browser files, such as IndexedDB, Local Storage, Preferences, Login Data, Web Data and other databases containing cookies, saved sessions, and user profile information.

Even if some of these files are currently being used by the browser, Umbrij has a forced copy mechanism to complete the process without interruption.

Seizing the active Gmail session

Once the necessary files are collected, the tool launches Chrome or Edge in headless using the copied profile. This loads all of the user's active cookies, allowing the browser to assume that the Google account is already logged in.

To automate the process, Puppeteer, a popular JavaScript library that allows full control of Chromium-based browsers via the Chrome DevTools Protocol.

The tool sends an authorization request to Google servers using a client ID that corresponds to the Google Workspace migration tool from Microsoft Outlook and Microsoft Exchange.

It then simulates mouse movements and user selections, so that the permissions granting process can be completed without human intervention.

This way, attackers gain access not only to Gmail, but also to services such as Google Drive, Contacts, Calendar, and Tasks, depending on the permissions requested.

From authorization code to access token

When the process is complete, Umbrij extracts the OAuth Authorization Code, which it stores in a log file along with all the actions it performed during the attack.

See also: ToddyCat: Uses “disposable” malware for attacks

ToddyCat hackers later retrieve the specific file from the compromised system and exchange the password for a valid OAuth Access Token.

This token is used to connect to Gmail through the official Google API, without requiring the password again or any new authentication process.

ToddyCat: New Umbrij malware targets corporate Gmail accounts

How can organizations be protected?

Kaspersky recommends that system administrators carefully review applications authorized to access corporate Google accounts.

In particular, it is recommended to inspect the connected apps management page in your Google Account and look for apps such as Google Workspace Migration for Microsoft Outlook or Google Workspace Sync for Microsoft Outlook. If these apps are not actually used by the organization, their access should be revoked immediately by revoking the associated OAuth tokens.

At the same time, experts emphasize the importance of continuous monitoring of corporate endpoints, timely installation of security updates, and detection of suspicious activity in browsers and Google Workspace accounts.

Cyber ​​espionage is evolving

As Kaspersky Senior Malware Analyst Andrey Gunkin, ToddyCat continues to invest in developing tools that automate the hacking of corporate email accounts. The use of Umbrij proves that modern APT groups no longer rely solely on software vulnerabilities, but exploit legitimate features of popular services and applications to remain invisible.

This campaign is yet another reminder that protecting corporate accounts is not just about strong passwords or multi-factor authentication. Constant monitoring of OAuth permissions, regular auditing of connected applications, and early detection of unusual activity are now essential elements of a comprehensive cybersecurity strategy against increasingly sophisticated threats.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS