Threats Tagged 'tomberbil'
View all threats tagged with 'tomberbil'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tomberbil'
Click on any threat for detailed analysis and mitigation recommendations
The ToddyCat APT group developed a sophisticated tool called Umbrij to compromise Gmail corporate accounts through OAuth token theft. The malware exploits Chromium-based browsers by launching them in headless mode with remote debugging enabled, utilizing the Shadow Token via Remote Debug (STRD) technique. Umbrij automates the entire attack chain: it copies user profiles, launches browsers with debugging ports, connects via Puppeteer Sharp library, and manipulates OAuth flows by impersonating legitimate Google Workspace migration tools. The tool specifically targets client IDs for Google Workspace Migration for Microsoft Outlook and Google Workspace Sync applications, requesting extensive permissions for email, calendar, drive, and contacts. ToddyCat deploys Umbrij through DLL sideloading techniques using signed files from Bitdefender, Visual Studio, and Google Desktop Search. This automated approach enables scalable compromise of organizational email communications while evading traditional security monito... Join the discussion | AlienVault OTX General | 06/30/2026, 11:56:29 UTC Added: 06/30/2026, 14:06:41 UTC |
The ToddyCat APT group has developed advanced tools and techniques to covertly access corporate email data by targeting both on-premises Outlook OST files and Microsoft 365 cloud environments. Their toolkit includes PowerShell-based TomBerBil for extracting browser data, TCSectorCopy for copying Outlook OST files, and methods to steal OAuth tokens from Microsoft 365 processes. They leverage SMB for remote file access, dump process memory, and search for access tokens to bypass security monitoring. These tactics enable stealthy data theft of sensitive email content and credentials. Detection guidance is available for each technique to help defenders identify and mitigate these intrusions. The threat is assessed as medium severity due to the complexity and targeted nature of the attacks, with no known exploits in the wild yet. European organizations using Microsoft 365 and Outlook are at risk, especially those with valuable email communications and cloud integrations. Join the discussion | AlienVault OTX General | 11/21/2025, 14:38:00 UTC Added: 11/21/2025, 22:16:22 UTC |
Showing 1 to 2 of 2 results