ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens
ToddyCat, a threat actor, has been seen using new techniques, such as a bespoke tool called TCSectorCopy, to gain access to target firms' corporate email data.
According to a technical breakdown by Kaspersky, this attack enables them to collect tokens for the OAuth 2.0 authorization protocol using the user's browser, which may be utilized outside the perimeter of the compromised infrastructure to access business mail.
ToddyCat, which has been active since 2020, has a history of using tools like Samurai and TomBerBil to target different enterprises in Europe and Asia in order to maintain access and steal passwords and cookies from web browsers like Google Chrome and Microsoft Edge.
The hacking organization was identified earlier in April for using a security vulnerability in ESET ...


