Threat reportAPTTL-2026-1072
ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow Token via Remote Debug' (STRD) to Access Gmail, Drive, Calendar and Contacts
ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow (TL-2026-1072), also tracked as STRD, is a high-severity advanced persistent threat campaign, first published 2026-07-02. It is attributed to ToddyCat with medium confidence, affects Google Chrome, maps to 14 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 1ToddyCat
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-1072
- Threat ID
- TL-2026-1072
- Also known as
- STRD, Shadow Token via Remote Debug
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- ToddyCat
- Attribution confidence
- MEDIUM
- Motivation
- ESPIONAGE
- Target sectors
- government administration, military, defense-contractors, corporate-enterprise
- Target regions
- Europe, Asia, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow
Malware and tooling: Umbrij, Puppeteer Sharp
How ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow works
Kaspersky attributes a new .NET-based credential theft tool named Umbrij to the ToddyCat APT group. Umbrij is deployed via DLL side-loading on three signed legitimate executables and launches a hidden, headless Chromium browser with remote debugging enabled to automate an OAuth authorization-code grab through the Chrome DevTools Protocol, exchanging it for an access token that grants API access to a victim's Gmail, Drive, Calendar, Contacts and Tasks without needing credentials or triggering a new login.
ToddyCat, an APT group active since at least December 2020 that has historically targeted government, military and military-contractor organizations across Europe and Asia (initially Taiwan and Vietnam via Microsoft Exchange/ProxyLogon, later expanding to Afghanistan, India, Iran, Malaysia, Pakistan, Russia, Slovakia, Thailand, Kyrgyzstan, Uzbekistan, Indonesia and the UK), has been linked by Kaspersky's GReAT team to a new .NET credential-theft tool called Umbrij (observed in versions a, b and c; Kaspersky detections HEUR:Trojan-PSW.MSIL.Umbrij.gen, HEUR:Trojan.MSIL.Agent.gen, HEUR:Trojan-PSW.MSIL.Agent.gen). Umbrij is packed with the open-source ConfuserEx .NET obfuscator to hinder static analysis and reverse engineering.
Umbrij is delivered to compromised Windows hosts via DLL side-loading against three legitimately signed executables: BDSubWiz.exe (Bitdefender ConnectAgent, side-loads log.dll), VSTestVideoRecorder.exe (Microsoft Visual Studio Test component, side-loads Microsoft.VisualStudio.QualityTools.VideoRecorderEngine.dll), and GoogleDesktop.exe (Google Desktop Search, side-loads GoogleServices.dll). Attackers copy the legitimate signed binary and the malicious loader DLL into user-writable locations such as C:\Users\Public\ and C:\windows\vss\, and have been observed persisting via a scheduled task masquerading under the name 'KasperskyEndpointSecurityEDRAvp' to blend in with legitimate Kaspersky endpoint security tooling.
Once running, Umbrij enumerates local Chromium browser profiles (Chrome and Edge) via command-line flags (-regex to match a target email substring, -user to scope to a Windows user, -browser to choose msedge/chrome/both, -deepsearch for verified profile matching, -savepdf to screenshot matched profiles as PDF evidence). For each matched profile it copies profile artifacts needed to reproduce an authenticated browsing context — IndexedDB, Local Storage, Network cache, Login Data, Login Data For Account, Preferences, Secure Preferences, Web Data and the top-level Local State JSON (normally at %LOCALAPPDATA%\Google\Chrome\User Data\Local State) — into a working directory.
Umbrij then launches a hidden/headless instance of the target Chromium browser using the copied profile with the flags --headless and --remote-debugging-port=<port>, and uses the Puppeteer Sharp .NET library to drive the browser over the Chrome DevTools Protocol (CDP). Because the copied profile already contains valid Google authentication cookies, Google treats the automated session as the legitimate, already-authenticated user and does not prompt for re-authentication or MFA. Umbrij programmatically navigates to Google's OAuth2 authorization endpoint (accounts.google.com/o/oauth2/v2/auth) impersonating one of two pre-registered, Google-verified third-party OAuth client applications — 'Google Workspace Migration for Microsoft Outlook' (GWMMO, client ID 279448736670) or, when the -sync flag is used, 'Google Workspace Sync for Microsoft Outlook' (GWSMO, client ID 1095133494869) — and requests broad delegated scopes covering Gmail (mail.google.com), Drive, Calendar, Admin Directory, Contacts and Tasks. Because the session is already authenticated and the OAuth client is a Google-trusted first/third-party integration, Google's consent flow silently issues an authorization code in the redirect URL, which Umbrij intercepts via CDP network inspection and exchanges directly for an OAuth access (and refresh) token via the Google token endpoint — without ever touching the account password, without an interactive consent screen in many enterprise/Workspace configurations, and without generating a traditional 'new sign-in' security alert. Kaspersky has named this technique 'Shadow Token via Remote Debug' (STRD). The resulting access token gives the attacker durable, credential-less API access to the victim's Gmail, Drive, Calendar, Contacts and Tasks data, functioning as a stealthy, non-malware persistence and collection mechanism that survives password resets (until the OAuth grant is explicitly revoked at myaccount.google.com/connections).
Umbrij is assessed as a purpose-built successor/companion to ToddyCat's previously documented email-theft toolset TCSectorCopy (disclosed November 2025), which targeted Microsoft Outlook/M365 access tokens; Umbrij instead pivots the same operational goal — silent, token-based access to a victim's corporate email and cloud productivity data — onto the Google Workspace/Gmail ecosystem. Kaspersky's defensive guidance includes auditing and revoking suspicious third-party OAuth grants (especially GWMMO/GWSMO if not deployed by IT), disabling remote debugging via the Chrome/Edge Group Policy key HKLM\Software\Policies\Google\Chrome\DeveloperToolsAvailability (set to 2), and hunting for browser processes launched with simultaneous --headless and --remote-debugging-port flags.
MITRE ATT&CK techniques used in TL-2026-1072
Collection
T1005 Data from Local System; T1113 Screen Capture; T1114 Email Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1134 Access Token Manipulation; T1574 Hijack Execution Flow
Persistence
Execution
Discovery
Command and Control
Privilege Escalation
T1134 Access Token Manipulation
collection
T1185 Browser Session Hijacking
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
lateral-movement
T1550 Use Alternate Authentication Material
Lateral Movement
T1550 Use Alternate Authentication Material
stealth
Affected products and versions in ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow
- Google — Chrome
Vulnerable versions: all Chromium-based Chrome versions supporting --remote-debugging-port - Microsoft — Edge
Vulnerable versions: all Chromium-based Edge versions supporting --remote-debugging-port - Google — Gmail / Google Workspace (OAuth API access)
Vulnerable versions: accounts with active browser sessions and no OAuth app allow-listing - Bitdefender — BDSubWiz.exe (ConnectAgent) - DLL side-loading vector
Vulnerable versions: insecure DLL search order load of log.dll - Microsoft — VSTestVideoRecorder.exe (Visual Studio Test) - DLL side-loading vector
Vulnerable versions: insecure DLL search order load of Microsoft.VisualStudio.QualityTools.VideoRecorderEngine.dll - Google — GoogleDesktop.exe (Google Desktop Search) - DLL side-loading vector
Vulnerable versions: insecure DLL search order load of GoogleServices.dll
Remediation for ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow
Immediate actions
- Audit and revoke suspicious third-party OAuth application grants at myaccount.google.com/connections, especially any 'Google Workspace Migration for Microsoft Outlook' (client ID 279448736670) or 'Google Workspace Sync for Microsoft Outlook' (client ID 1095133494869) grants not explicitly deployed by IT
- Hunt for and terminate any Chrome/Edge processes launched with simultaneous --headless and --remote-debugging-port command-line flags
- Search for scheduled tasks named or masquerading as 'KasperskyEndpointSecurityEDRAvp' that do not correspond to a genuine Kaspersky EDR deployment
- Hunt for BDSubWiz.exe, VSTestVideoRecorder.exe, or GoogleDesktop.exe running from non-standard paths such as C:\Users\Public\ or C:\windows\vss\, or alongside unexpected sibling DLLs (log.dll, Microsoft.VisualStudio.QualityTools.VideoRecorderEngine.dll, GoogleServices.dll)
- Force sign-out of active Google sessions and rotate/re-authenticate corporate Google Workspace accounts suspected of compromise
Workarounds
- Disable Chrome/Edge remote debugging enterprise-wide via Group Policy key HKLM\Software\Policies\Google\Chrome\DeveloperToolsAvailability (and the Edge equivalent under Microsoft\Edge) set to value 2 (disallow for extensions and DevTools alike)
- Block outbound network access to the local browser remote-debugging port range from non-browser processes via host firewall rules
- Enforce Google Workspace context-aware access / IP allow-listing to reduce the value of stolen OAuth tokens used from attacker infrastructure
Longer-term hardening
- Deploy Google Workspace security investigation tool alerting on new OAuth token grants for high-privilege scopes (mail, drive, admin.directory)
- Enable and monitor Google Workspace login and OAuth token audit logs (Admin console > Reports) for anomalous token issuance from non-corporate IP ranges
- Restrict which third-party OAuth applications can be authorized in Google Workspace via API access control allow-listing
- Deploy EDR coverage for DLL side-loading detection (unsigned/unexpected DLL loaded by a signed parent binary) with focus on the three identified vulnerable executables
- Implement application allow-listing / code integrity policies to block execution of copied signed binaries from user-writable directories
Timeline of ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow
- ToddyCat APT group first observed by Kaspersky, initially targeting government entities in Taiwan and Vietnam via compromised Microsoft Exchange servers
- Following ProxyLogon exploitation, ToddyCat targeting expands to Afghanistan, India, Iran, Malaysia, Pakistan, Russia, Slovakia, Thailand, Kyrgyzstan, Uzbekistan, Indonesia and the UK
- Kaspersky publishes 'ToddyCat: Unveiling an unknown APT actor attacking high-profile entities in Europe and Asia', the first public profile of the group
- Kaspersky/researchers disclose ToddyCat's TCSectorCopy tool targeting Microsoft Outlook emails and Microsoft 365 access tokens
- DataBreaches.net republishes Kaspersky's findings on the Umbrij toolkit and corporate Gmail compromise vector
- Kaspersky GReAT publishes technical analysis (part two of its ToddyCat research) of the Umbrij .NET credential-theft tool and the 'Shadow Token via Remote Debug' (STRD) OAuth abuse technique, including IOCs and detection guidance
- Kaspersky Managed Detection and Response (MDR) analysts detect a scheduled task masquerading as 'KasperskyEndpointSecurityEDRAvp' during a proactive threat hunting operation, the initial lead that uncovers the Umbrij tool and the STRD OAuth-abuse technique
- Russian-language technical press outlets (xakep.ru, ixbt.com, Securelist.ru mirror) publish coverage of the Kaspersky Umbrij/STRD findings, broadening regional awareness
- Follow-up technical writeups published by GBHackers and CyberPress summarizing the Umbrij/STRD research
- The Hacker News publishes coverage of the ToddyCat-linked Umbrij malware and STRD OAuth abuse technique, broadening public awareness
Sources cited for ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow
- How the ToddyCat APT group gains access to Gmail accounts
- ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
- ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts
- ToddyCat APT Automates Gmail Account Compromise With ConfuserEx-Obfuscated .NET Tool
- ToddyCat: Unveiling an unknown APT actor attacking high-profile entities in Europe and Asia
- ToddyCat's New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens
- Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts
Detection coverage for TL-2026-1072
As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1072 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.