ToddyCat: your hidden email assistant. Part 2


Kaspersky continue to share details on the malicious techniques and toolsets used by the ToddyCat APT group. In the first part of this report, they examined the group’s attacks aimed at stealing data from browsers, as well as from local and cloud email services. The methods used in that campaign indicated that ToddyCat was attempting to access corporate correspondence while evading monitoring tools. However, all of the group’s methods Kaspersky described previously are effectively detected by EPP and EDR solutions.

The attackers continued their search for ways to bypass security solutions and developed a new tool to gain access to a victim’s cloud account via the Google API. Armed with this tool, the group automated all stages of the attack and managed to remain undetected by monitoring systems.

Read more…
Source: Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • ‘Several combinations of social engineering’ used during cyberattack on camera maker Axis

    March 3, 2022

    Camera maker Axis released more details about a cyberattack that started on the night of Saturday, February 19. In its initial messages on its website, the Swedish camera giant said it got alerts from its cybersecurity and intrusion detection system on Sunday, February 20, before it shut down all public-facing services globally in the hopes of ...

  • NVIDIA DLSS source code leaked as part of cyberattack

    March 2, 2022

    The attack on NVIDIA continues, this time with an alleged leak of the source code for the company’s DLSS tech. A ransomware group known as Lapsus has allegedly shared NVIDIA’s DLSS source code as part of a cyberattack. The group has demanded that NVIDIA remove mining limitations from RTX 30-series graphics cards. The leaked DLSS source code ...

  • Conti ransomware group’s source code leaked

    March 2, 2022

    Infamous ransomware group Conti is now the target of cyberattacks in the wake of its announcement late last week that it fully supports Russia’s ongoing invasion of neighboring Ukraine, with the latest hit being the leaking of its source code for the public to see. This disclosure comes just days after an archive leaked containing more ...

  • SMS PVA Part 3: Countries Most Impacted by Service

    March 2, 2022

    Part two of our blog entry discussed the impacts and implications of SMS PVA services. The article also explored how these services work by using Carousell as an example. Moreover, it discussed the “benefits” of SMS PVA services to cybercriminals. In the final installation of our series, we’ll discuss relevant statistics and recommendations to mitigate the ...

  • TeaBot Android Banking Trojan continues its global conquest with new upgrades

    March 2, 2022

    The TeaBot Remote Access Trojan (RAT) has been upgraded, leading to a huge increase in both targets and spread worldwide. On March 1, the Cleafy research team said TeaBot now targets over 400 applications, pivoting from an earlier focus on “smishing” to more advanced tactics. Smishing attacks are used to compromise mobile handsets via spam text messages ...

  • DDoS attackers have found this new trick to knock over websites

    March 2, 2022

    Distributed denial of service (DDoS) attackers are using a new technique to knock websites offline by targeting vulnerable ‘middleboxes’, such as firewalls, to amplify junk traffic attacks. Amplification attacks are nothing new and have helped attackers knock over servers with short busts of traffic as high as 3.47 Tbps. Microsoft last year mitigated attacks on this ...