The ToddyCat advanced persistent threat group has adopted new techniques that let attackers reach internal corporate communications even when companies rely on cloud email platforms. The group now uses browser-based token theft and network-level data collection to bypass traditional defenses. Security researchers at Securelist documented how these operations evolved through late 2024 and early 2025. Their findings show a clear shift toward low-noise attacks that blend into normal network activity.
Relevant Source (Kaspersky Securelist): ToddyCat: your hidden email assistant. Part 1
Kaspersky researchers document ToddyCat’s new tools and techniques for stealing browser data, OAuth 2.0 tokens, and Outlook email to covertly access corporate communications, which directly supports the methods described in this section.
Quick Facts
- ToddyCat now targets OAuth 2.0 tokens from employee browsers.
- The attacks allow access to Microsoft 365 and Gmail without staying in the victim network.
- A new PowerShell version of the TomBerBil tool harvests browser files remotely.
- Tools collect saved passwords, cookies, encryption keys, and email access tokens.
- SMB-based file collection helps the activity look like everyday network traffic.
- Securelist researchers confirm rapid evolution in ToddyCat’s methods.
Understanding ToddyCat’s New Tactics
ToddyCat has shifted away from traditional intrusion techniques and toward browser-focused credential theft that targets cloud email access. The group captures OAuth 2.0 tokens through a victim’s browser, which grants attackers near-direct entry to corporate email accounts. This method bypasses many detection controls that depend on monitoring internal hosts or mail servers.
- Attackers rely on browser data to reach Microsoft 365 and Gmail mailboxes.
- Stolen tokens allow email access even after they leave the network.
- Tools gather passwords, encryption keys, and session data.
This shift reflects an interest in stealthy operations that blend with routine traffic. The approach also reduces the need to maintain a presence in the target’s environment, which limits exposure when defenders investigate.
Relevant Source (Microsoft Security Blog): Token tactics: How to prevent, detect, and respond to cloud token theft
Microsoft describes how attackers steal and replay OAuth tokens to reach cloud resources like email, supporting the risks outlined in this section.
Why These Attacks Matter
Cloud email services create a sense of safety because data stays off the company network, yet token theft breaks this assumption. The new techniques show that browser-side security weaknesses can compromise entire mail systems. Organizations often overlook these areas because they seem unrelated to email security.
- Attackers no longer need full network access to read internal mail.
- Email compromise continues even after malware is removed locally.
- SMB-based data theft can be mistaken for normal admin activity.
- Encryption keys harvested from browsers let attackers decrypt everything offline.
- Continuous refinement makes each generation of tools harder to detect.
These developments highlight the need for stronger identity controls. Companies that rely only on cloud security features risk leaving a large blind spot in their defenses.
Relevant Source (Microsoft Incident Response): Microsoft incident response lessons on preventing cloud identity compromise
Microsoft outlines how token theft and cloud identity compromise let attackers maintain access to email and other services even after initial malware is removed, which matches the risks described in this section.
Relevant Source (CISA): Securing Core Cloud Identity Infrastructure: Addressing Advanced Threats Through Public-Private Collaboration
CISA highlights that identity-focused attacks on cloud services are a primary vector for modern intrusions and stresses stronger identity controls, directly supporting the need for tighter protections discussed here.
What Security Teams Should Do
Teams should focus on browser security, identity protection, and strict monitoring of high-privilege systems. The TomBerBil PowerShell update shows that domain controllers remain top targets because attackers use them to reach every endpoint on the network.
Steps to take:
- Enforce conditional access policies tied to device trust and location.
- Block or tightly monitor SMB connections between privileged systems and user endpoints.
- Secure browser data using stronger profile isolation and mandatory hardware-based encryption.
- Rotate OAuth tokens when suspicious activity is detected.
- Audit PowerShell execution and limit bypass permissions.
These controls help limit an attacker’s ability to gather encryption keys or reuse stolen tokens. Defenders gain more visibility and shrink the window for token-based compromise.
Relevant Source (CISA): Weak Security Controls and Practices Routinely Exploited for Initial Access
CISA details how attackers abuse poor identity protections, unmonitored PowerShell use, and weak network controls, directly supporting the need for logging, SMB monitoring, and hardening privileged systems in this section.
Relevant Source (Microsoft Entra Blog): Addressing data exfiltration: token theft talk
Microsoft outlines practical defenses against token theft, including conditional access, device protection, and token protection policies that align with the recommended steps for securing browsers, identities, and OAuth tokens in this section.
The Big Picture
ToddyCat’s evolution shows how threat groups adapt when organizations shift to cloud-first communication systems. Email may sit in the cloud, but the keys to access it remain inside local browsers, which gives attackers a soft entry point. Tools that quietly collect passwords, cookies, and local encryption material expose a wide set of risks that are not addressed by traditional mail security products.
The broader trend is clear. Advanced groups are moving toward identity-centric attacks instead of heavy malware deployment. By blending in with normal traffic and collecting data through SMB shares, these operations reduce alarms while gaining long-term access. Security strategies need to match this reality and protect user identity, browser data, and token lifecycles with the same rigor once applied to on-premise servers.
Relevant Source (Sygnia): Sygnia’s 2025 Field Report: The Rise of Identity-Based Attacks
Sygnia’s threat report describes the broader industry shift toward identity-centric intrusions and stolen credentials, which aligns with the trend toward token and browser data abuse highlighted in this section.
Stronger Defense Steps
Organizations should strengthen identity security because token theft now acts as a main entry point for email compromise. A clear focus on browser hardening, credential protection, and SMB visibility gives defenders a practical path to reducing exposure.
Common Questions
How does ToddyCat reach cloud email accounts?
They use stolen OAuth 2.0 tokens captured from browser data on compromised systems.
Why do SMB connections help attackers hide?
SMB traffic between admin systems and endpoints often looks normal, so it draws less attention.
Can attackers decrypt browser files easily?
Yes, if they steal the DPAPI keys and encryption materials copied by the TomBerBil tool.
Does removing malware stop the email access?
No. Token theft allows access to continue unless tokens are revoked or rotated.
Are Microsoft 365 and Gmail equally at risk?
Any service that uses OAuth tokens is vulnerable if an attacker steals the associated browser data.
How JENI Strengthens Your Security Posture
JENI helps organizations close the gaps that threats like ToddyCat rely on. The platform focuses on system integrity, performance stability, and endpoint hardening in ways that support broader cybersecurity work. Strong endpoint hygiene reduces the surface area attackers use when stealing tokens, browser data, or authentication keys.
What JENI Delivers
- Automated cleanup that reduces hidden system clutter attackers often exploit.
- Stability checks that help prevent corruption in browser profiles and cached credentials.
- Endpoint optimization that supports stronger identity and token protection.
JENI complements existing security tools by improving the health of the systems attackers target first. A healthier device environment lowers the odds of unnoticed browser weaknesses or misconfigurations. Organizations gain more resilience against identity-driven attacks when endpoints stay clean and predictable. Strong performance and consistency across devices creates a tougher environment for quiet, stealth-based intrusions.

