>samit_hota
Back to adversary profiles

Threat Actor Dossier

ToddyCat (G1022): Evolving Cyber Espionage Operations

G1022

5 sectors targeted

Threat level
HIGH
Status
ACTIVE
Origin
Suspected China
Motivation
Espionage · Information Theft
Samit Hota·
Target Sectors
Government, Military, Diplomatic, Telecommunications, High-profile organizations
Associated Malware
Samurai, Ninja, TomBerBil, TCESB, Umbrij, TCSectorCopy, China Chopper, Cuthead, WAExp, CurKeep, CurLu, CurCore, LoFiSe, DropBox Uploader, Pcexter, Cobalt Strike
#threat-actor#g1022

Overview

ToddyCat, tracked as G1022, is a sophisticated Advanced Persistent Threat (APT) group that has been actively conducting cyber espionage campaigns since at least December 2020. This group is known for its advanced technical capabilities, employing custom loaders and malware in multi-stage infection chains to achieve its objectives. While no conclusive attribution has been publicly made linking ToddyCat to explicit state actors, analysis of their operational characteristics, targeting patterns, and toolset similarities strongly suggests potential affiliations with Chinese state-sponsored cyber initiatives.

ToddyCat’s primary motivation is information theft and espionage, focusing on extracting sensitive data from high-profile entities within strategic sectors linked to geopolitical interests. The group consistently targets government, military, and diplomatic organizations across Europe and Asia, with specific past campaigns observed against entities in Taiwan, Vietnam, India, Russia, Iran, the United Kingdom, Indonesia, Uzbekistan, Kazakhstan, and Slovakia. Their operations demonstrate a sustained interest in geopolitical objectives and a commitment to refining their tactics and tools to maintain persistence and evade detection.

Tactics & Techniques

ToddyCat employs a diverse and evolving set of tactics, techniques, and procedures (TTPs) to gain initial access, maintain persistence, and exfiltrate data. Initial access often leverages vulnerabilities in publicly exposed Microsoft Exchange servers, notably the ProxyLogon vulnerability (CVE-2021-26855). The group also distributes malware through spear-phishing emails containing malicious archives that exploit DLL side-loading techniques.

For Persistence, ToddyCat utilizes scheduled tasks and creates registry keys and services to ensure their malicious code is loaded during system startup. They have been observed creating scheduled tasks disguised as legitimate system services or security software components, such as “AppleNotifyService” or “KasperskyEndpointSecurityEDRAvp”.

Defense Evasion is a hallmark of ToddyCat’s operations. They frequently employ DLL side-loading, where a legitimate executable from a trusted application is used to load a malicious DLL. This technique allows their payloads to execute within trusted processes, often inheriting the legitimate application’s digital signature and bypassing security products. More recently, they have adopted sophisticated methods like the “Bring Your Own Vulnerable Driver” (BYOVD) technique and exploited vulnerabilities in security software, such as an ESET scanner flaw (CVE-2024-11859), to execute payloads stealthily. They also rename digitally signed VPN server executables to conceal their true purpose.

For Credential Access and Discovery, ToddyCat uses tools like TomBerBil to steal passwords and other data from web browsers (Chrome, Edge, Firefox) and collects Windows Data Protection API (DPAPI) encryption keys for offline decryption. They have been seen executing commands like net group "domain admins" /dom and tasklist for network and process enumeration. They also perform extensive discovery activities, including domain enumeration and scanning for files of interest.

Lateral Movement is achieved through locally mounted SMB shares, often utilizing compromised domain admin credentials. They also establish reverse SSH tunnels and use SoftEther VPN server utilities for tunneling, ensuring redundant access to compromised infrastructure.

Collection and Exfiltration of data are highly refined. ToddyCat employs tools like Cuthead to search for specific file types or keywords and store them in archives. WAExp is used to steal data from the web version of WhatsApp. A custom C++ utility named TCSectorCopy is designed to bypass file locks and copy Outlook offline storage files (OST) sector-by-sector, which can then be parsed using tools like XstReader to access corporate correspondence. The group also developed Umbrij, a tool to steal Gmail and Google Workspace OAuth tokens via the Google API, gaining persistent access to corporate email. Stolen data is frequently compressed with utilities like WinRAR and exfiltrated over C2 channels, including public services like DropBox and Microsoft OneDrive.

Notable Campaigns

ToddyCat’s operations have shown a consistent pattern of evolution and adaptation.

  • December 2020 - February 2021: The group initiated its activities by targeting a limited number of Microsoft Exchange servers in Taiwan and Vietnam, deploying the China Chopper web shell through an unidentified vulnerability. This led to the installation of custom loaders and the Samurai backdoor.
  • February - May 2021: ToddyCat rapidly escalated its attacks, abusing the ProxyLogon vulnerability to compromise numerous high-profile organizations across Europe and Asia, including in India, Russia, Iran, and the UK.
  • September 2021: The group expanded its focus to desktop systems in Central Asia, distributing the Ninja Trojan via Telegram in zip archives.
  • Early 2024: Kaspersky detected a new complex tool, TCESB, designed to exploit vulnerabilities in ESET command-line scanners to execute payloads stealthily.
  • May - June 2024: ToddyCat deployed a PowerShell variant of their TomBerBil malware, operating from domain controllers with privileged accounts. This variant harvested browser data (Chrome, Edge, Firefox) and DPAPI keys via SMB shares.
  • Late 2024 - Early 2025: A significant shift in tooling focused on extracting Outlook mail archives using TCSectorCopy and harvesting Microsoft 365 access tokens from memory using tools like SharpTokenFinder and ProcDump.
  • July 2026: New malware dubbed Umbrij was attributed to ToddyCat, designed to gain surreptitious access to victim email correspondence via the Google API, leveraging OAuth tokens stolen through a technique called Shadow Token via Remote Debug (STRD).

Associated Malware & Tools

ToddyCat’s toolkit is extensive, featuring both custom-developed malware and legitimate or commodity tools repurposed for malicious ends.

  • Samurai Backdoor: A sophisticated, modular passive backdoor used for remote administration and lateral movement, often a final stage component in Exchange server compromises.
  • Ninja Trojan: A versatile agent featuring file management, reverse shell capabilities, process management, code injection, and network traffic forwarding, designed for deep penetration and stealth.
  • China Chopper: A small, well-known web shell used for initial access and execution on compromised Exchange servers.
  • TomBerBil: A credential stealer (C++, C#, and PowerShell variants) that targets data from popular web browsers (Chrome, Edge, Firefox) and is capable of capturing DPAPI master keys for offline decryption.
  • TCESB: A complex tool designed to exploit vulnerabilities in ESET command-line scanners to execute payloads stealthily.
  • TCSectorCopy: A C++ utility designed to bypass file locks and copy Outlook offline storage files (OST) sector by sector.
  • Umbrij: A .NET post-compromise tool specifically developed to steal Gmail and Google Workspace OAuth tokens via the Google API and browser remote debugging.
  • Cuthead: A .NET-compiled tool used to search for specific documents based on extensions or keywords and archive them.
  • WAExp: A .NET application designed to steal data from the web version of WhatsApp by copying browser local storage files.
  • CurKeep, CurLu, CurCore, CurLog: Various loaders and downloaders observed in campaigns, often employing DLL side-loading. CurCore, in particular, can create files, execute remote commands, and exfiltrate data.
  • LoFiSe: A file tracker and stealer used for finding specific files.
  • SharpTokenFinder: A tool used to hunt for plaintext Microsoft 365 OAuth tokens in system memory.
  • ProcDump: A Sysinternals tool leveraged to extract authentication material (tokens) from running email processes when other methods are blocked.
  • Cobalt Strike: A commercial penetration testing framework widely adopted by threat actors for post-exploitation activities, including loading other malware like Ninja.
  • Data Exfiltration Utilities: WinRAR for compression, and direct uploaders for public file hosting services like DropBox and Microsoft OneDrive (Pcexter).
  • Traffic Tunneling Tools: Reverse SSH tunnels, SoftEther VPN (often renamed), Ngrok, and Krong are used to obscure presence and maintain access.
  • Passive UDP Backdoor: Used for persistence, receiving commands over UDP packets.
  • FRP Client (Fast Reverse Proxy): A high-speed reverse proxy based on Golang, used to obscure their presence.

Current Status

ToddyCat remains a very active and evolving threat actor. Recent intelligence indicates continuous refinement of their operational tactics and malware toolset. Campaigns have been observed throughout 2024, 2025, and into mid-2026, demonstrating their persistent engagement in cyber espionage. The group consistently adapts to new security measures and conditions, evidenced by their shift from browser credential theft to stealing entire Outlook archives and Microsoft 365 access tokens, and their exploitation of security software vulnerabilities. Their latest developments, such as the Umbrij tool for Gmail OAuth token theft, highlight a sustained focus on compromising corporate email communications and an ability to leverage novel techniques to bypass traditional defenses. Organizations in their target regions and sectors should consider ToddyCat an ongoing and highly capable threat.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call