Tag: ToddyCat

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens
News

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens

ToddyCat, a threat actor, has been seen using new techniques, such as a bespoke tool called TCSectorCopy, to gain access to target firms' corporate email data. According to a technical breakdown by Kaspersky, this attack enables them to collect tokens for the OAuth 2.0 authorization protocol using the user's browser, which may be utilized outside the perimeter of the compromised infrastructure to access business mail. ToddyCat, which has been active since 2020, has a history of using tools like Samurai and TomBerBil to target different enterprises in Europe and Asia in order to maintain access and steal passwords and cookies from web browsers like Google Chrome and Microsoft Edge. The hacking organization was identified earlier in April for using a security vulnerability in ESET ...
New TCESB Malware Found in Active Attacks Exploiting ESET Security Scanner
News

New TCESB Malware Found in Active Attacks Exploiting ESET Security Scanner

A threat actor with ties to China, well-known for its cyberattacks in Asia, has been seen delivering an as-yet-undiscovered virus called TCESB by taking advantage of a security hole in ESET's security software. According to an investigation released this week by Kaspersky, [TCESB], which was not previously observed in ToddyCat assaults, is made to covertly carry out payloads in order to get beyond security and monitoring technologies that are installed on the device. A threat activity cluster known as "ToddyCat" has been responsible for attacks on multiple Asian entities since at least December 2020. The hacker gang used a variety of technologies to sustain continuous access to infiltrated environments and collect data on a "industrial scale" from Asia-Pacific enterprises, accord...