Tag: ToddyCat-Linked

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
News

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

ToddyCat, a threat actor, has been linked to Umbrij, a new piece of malware that uses the Google API to secretly view a victim's email communication. According to a thorough analysis released this week by Kaspersky, the attackers concentrated on corporate email correspondence hosted on Gmail, aiming to compromise access through APIs. Applications can utilize an OAuth token to access requested email resources because the Google API uses the OAuth 2.0 protocol for permission. According to reports, the adversary created Umbrij in order to obtain this token and use it to establish a headless connection over a remote debugging port to the browser's management interface. In order to access the target resources through the API, a sequence of calls were made in order to obtain an OAuth a...