{"id":1579,"date":"2026-07-02T13:37:48","date_gmt":"2026-07-02T13:37:48","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1579"},"modified":"2026-07-02T13:37:48","modified_gmt":"2026-07-02T13:37:48","slug":"toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1579","title":{"rendered":"ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 02, 2026<\/span><\/span><span class=\"p-tags\">API Security \/ Cyberespionage<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhMMnC-1ujLiZRcV1xgXbB3qFoIREcbSiGqLCFID8-G-z8GFI3YEY8VniprVEBW4b4TZKJUvoRDg27elntNJWL9S6JZUHMMe1Ie1JLf9w5Fzsgx2w9c94ja1NoED4m3G1pNngC2DDWOOQPgVGiKOd0uBpZkQSSpFOo60S2Tbl8j2VWKdhb70sIJzF8d93LM\/s1700-e365\/gmail.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The threat actor known as <b>ToddyCat<\/b> has been attributed to a new malware called Umbrij that&#8217;s designed to gain surreptitious access to a victim&#8217;s email correspondence via the Google API.<\/p>\n<p>\u00abIn this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targeting access compromise via APIs,\u00bb Kaspersky <a href=\"https:\/\/securelist.com\/toddycat-apt-umbrij-tool-and-oauth\/120251\/\">said<\/a> in a detailed report published this week. \u00abBecause the Google API relies on the OAuth 2.0 protocol for authorization, applications can use an OAuth token to access requested email resources.\u00bb<\/p>\n<p>The adversary is said to have developed Umbrij to acquire this token and use it to connect to the browser&#8217;s management console in <a href=\"https:\/\/developer.chrome.com\/docs\/chromium\/headless\">headless mode<\/a> via a remote debugging port.<\/p>\n<p>Subsequently, a series of requests was issued to obtain an OAuth authorization code, which was then exchanged for an access token to reach the target resources via the API. The technique has been codenamed <b>Shadow Token via Remote Debug<\/b> (STRD) by the Russian cybersecurity vendor.<\/p>\n<p>What&#8217;s notable about the attack is that it&#8217;s viable on Chromium-based browsers and exploits an active Gmail session. In other words, the idea is to launch the browser in <a href=\"https:\/\/developer.chrome.com\/docs\/chromium\/headless\">headless mode<\/a>, connect via the remote debugging port to seize control, and leverage an already logged-in Gmail session to obtain access to the Google account resources.<\/p>\n<p>Three different versions of Umbrij have been uncovered, including versions that feature helper functions for debugging and for searching and selecting user accounts within the browser.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>ToddyCat is the name <a href=\"https:\/\/securelist.com\/toddycat-apt-steals-email-data-from-outlook\/118044\/\">assigned<\/a> to an advanced persistent threat (APT) that has a history of targeting various organizations in Europe and Asia since at least 2020. In November 2025, Kaspersky detailed the hacking group&#8217;s use of a custom tool dubbed TCSectorCopy to lay their hands on Microsoft Outlook email data belonging to targeted companies.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The cybersecurity company said it discovered Umbrij during what it described as a \u00abthreat hunting operation,\u00bb as part of which a scheduled task impersonating its software (\u00abKasperskyEndpointSecurityEDRAvp\u00bb) was used to launch a digitally signed file. The signed file then employed <a href=\"https:\/\/techzone.bitdefender.com\/en\/tech-explainers\/what-is-dll-sideloading.html\">DLL side-loading<\/a> to launch Umbrij.<\/p>\n<p>To accomplish this task, three legitimate binaries susceptible to DLL side-loading were abused &#8211;<\/p>\n<ul>\n<li><b>BDSubWiz.exe<\/b>, a component of the Submission Wizard in Bitdefender ConnectAgent<\/li>\n<li><b>VSTestVideoRecorder.exe<\/b>, a component of the video-recording tool used for testing with Microsoft Visual Studio<\/li>\n<li><b>GoogleDesktop.exe<\/b>, a discontinued Google Desktop Search application used for indexing files and performing quick searches on a local Windows computer<\/li>\n<\/ul>\n<p>Regardless of the executable used, the end result is the same: launching the rogue Umbrij DLL written in .NET and obfuscated with ConfuserEx, an open-source obfuscator. The tool can also be invoked along with command-line parameters that specify which browsers to target (Google Chrome or Microsoft Edge), instruct it to save a screenshot of the user profile as a PDF file, and provide the system username under which the tool will run.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgbZO0kjR_hpnvWUo5zTrdkC_uQ7yXP0z97m9uk0-m56yYNOHfynWPiAWaDKxMj6vr1-ZKKKO7iFSePxKZWHHcsmMQNz8WfZVTxXl98Rf4r8o5zqGQN9zUBpUQnhqLW2GLSjpBYYIU7ScCqWwZbK4dmEt-tu-ehJtgntUtdpNUb-UKDZNOeoALJTj2p0Naj\/s1700-e365\/kas.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgbZO0kjR_hpnvWUo5zTrdkC_uQ7yXP0z97m9uk0-m56yYNOHfynWPiAWaDKxMj6vr1-ZKKKO7iFSePxKZWHHcsmMQNz8WfZVTxXl98Rf4r8o5zqGQN9zUBpUQnhqLW2GLSjpBYYIU7ScCqWwZbK4dmEt-tu-ehJtgntUtdpNUb-UKDZNOeoALJTj2p0Naj\/s1700-e365\/kas.png\" alt=\"\" border=\"0\" data-original-height=\"988\" data-original-width=\"1890\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">Umbrij workflow diagram<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Umbrij, once launched, performs a series of preparatory actions on a compromised Windows host to breach the Gmail account &#8211;<\/p>\n<ul>\n<li>Verify the availability of the port that will be designated for browser debugging.<\/li>\n<li>Retrieve the user context by searching for the \u00abexplorer.exe\u00bb process and duplicating the token of the first such process it encounters in order to retain all of that logged-in user&#8217;s privileges. Alternatively, the -user <username> switch can be used alongside the tool to specify the target user whose token needs to be duplicated.<\/username><\/li>\n<li>Construct the path to the web browser application folder within the user&#8217;s local application data repository and then parse the Local State file corresponding to Chrome or Edge to gather information about stored browser user profiles.<\/li>\n<li>Enumerate all profiles and scan them for a field named \u00abuser_name\u00bb that includes an email address. It&#8217;s worth noting that the presence of an email address signals that the user is authenticated to a Google service.<\/li>\n<li>Create a directory called \u00abBackupFiles\u00bb within \u00ab%LOCALAPPDATA%\\Google\\Chrome\\\u00bb and \u00ab%LOCALAPPDATA%\\Microsoft\\Edge\\.\u00bb<\/li>\n<li>Copy the following files and folders of each target <a href=\"https:\/\/chromium.googlesource.com\/chromium\/src\/+\/HEAD\/docs\/user_data_dir.md\">user profile<\/a> into them: IndexedDB, Local Storage, Network, Login Data, Login Data For Account, Preferences, Secure Preferences, and Web Data. Should these files be locked by other processes, the tool includes a force-copy mechanism.<\/li>\n<li>Search the \u00abProgram Files\u00bb and \u00abProgram Files (x86)\u00bb folders for the browser installation folder for Chrome and Edge.<\/li>\n<li>Launch the browsers in headless mode by using the user profile copied to the \u00abBackupFiles\u00bb folder, causing the browser to apply all active user cookies, including the signed-in Google account, and skip authentication.<\/li>\n<li>Use <a href=\"https:\/\/pptr.dev\/\">Puppeteer<\/a>, a JavaScript library used for controlling Chromium-based browsers via the Chrome DevTools Protocol, to connect to the remote debugging port and send an authorization code request to direct the browser to a \u00abaccounts.google[.]com\/o\/oauth2\/v2\/auth\/identifier\u00bb URL containing a \u00abclient_id\u00bb that corresponds to a <a href=\"https:\/\/tools.google.com\/dlpage\/gsmmo\/\">migration tool<\/a> used for importing local PST files and data from Microsoft Exchange accounts into a Google Workspace account. The HTTP GET request also specifies the set of permissions required by the application. Use JavaScript to emulate mouse click events to select the appropriate Google account after navigating to the URL and grant it the necessary permissions, including full access to Gmail, Drive, Contacts, Calendar, and Tasks.<\/li>\n<li>Redirect the browser session to a local address specified in the initial request and extract the OAuth authorization code from it.<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqmM4NpfZsx4cw-HrXQlCjZQmrF8bYnmB23AmpOPi16kPNB9lvICjpdYEclxJwyQ9OE8GgzQ8aOEI68tRuxNqov0MHz2Sq8xEPiYWM3Js6FM5t2nm2JHWodmR7qVSot14ZtWVqQRQ6B88OnMaVxCPwRG7xGPoIIZxF6QAhWVhMkQfs11NjyNtHsGEUH4_q\/s728-e100\/sygnia-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abUmbrij, like most other tools in ToddyCat\u2019s arsenal, logs its actions in detail and saves them to a file,\u00bb Kaspersky said. \u00abIt also saves the retrieved authorization code to this log file, which the operator subsequently exfiltrates from the compromised host.\u00bb\u00a0<\/p>\n<p>\u00abThe acquired authorization code is then exchanged for an OAuth access token. The threat actors use that token to connect to the Gmail account through the API, thus compromising corporate email communications.\u00bb<\/p>\n<p>To counter the threat, it&#8217;s advised to review the authorization codes granted to applications by navigating to \u00abmyaccount.google[.]com\/connections\u00bb and then looking for applications named \u00abGoogle Workspace Migration for Microsoft Outlook\u00bb or \u00abGoogle Workspace Sync for Microsoft Outlook.\u00bb If either of those applications is present and is not actually used within the organization, it&#8217;s essential to revoke their access to invalidate the OAuth tokens.<\/p>\n<p>\u00abThe ToddyCat APT group continues to search for ways of compromising corporate email communications,\u00bb Andrey Gunkin, senior malware analyst at Kaspersky, said. \u00abTheir new tool, Umbrij, automates the attackers\u2019 attempts to gain access to organizational email accounts. This automation not only helps increase the scale and frequency of their attacks but also demonstrates ToddyCat\u2019s strong motivation and advanced technical skills.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 02, 2026API Security \/ Cyberespionage The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that&#8217;s designed to gain surreptitious access to a&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1580,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[226,130,14,2310,2,42,381,2308,2309],"class_list":["post-1579","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abuses","tag-access","tag-api","tag-gmail","tag-google","tag-malware","tag-oauth","tag-toddycatlinked","tag-umbrij"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1579"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1579\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1580"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}