# ToddyCat-Linked Umbrij Malware Abuses OAuth via 'Shadow Token via Remote Debug' (STRD) to Access Gmail, Drive, Calendar and Contacts

> Kaspersky attributes a new .NET-based credential theft tool named Umbrij to the ToddyCat APT group. Umbrij is deployed via DLL side-loading on three signed legitimate executables and launches a hidden, headless Chromium browser with remote debugging enabled to automate an OAuth authorization-code grab through the Chrome DevTools Protocol, exchanging it for an access token that grants API access to a victim's Gmail, Drive, Calendar, Contacts and Tasks without needing credentials or triggering a new login.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1072
- **ID:** TL-2026-1072
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** ToddyCat
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

ToddyCat, an APT group active since at least December 2020 that has historically targeted government, military and military-contractor organizations across Europe and Asia (initially Taiwan and Vietnam via Microsoft Exchange/ProxyLogon, later expanding to Afghanistan, India, Iran, Malaysia, Pakistan, Russia, Slovakia, Thailand, Kyrgyzstan, Uzbekistan, Indonesia and the UK), has been linked by Kaspersky's GReAT team to a new .NET credential-theft tool called Umbrij (observed in versions a, b and c; Kaspersky detections HEUR:Trojan-PSW.MSIL.Umbrij.gen, HEUR:Trojan.MSIL.Agent.gen, HEUR:Trojan-PSW.MSIL.Agent.gen). Umbrij is packed with the open-source ConfuserEx .NET obfuscator to hinder static analysis and reverse engineering.

Umbrij is delivered to compromised Windows hosts via DLL side-loading against three legitimately signed executables: BDSubWiz.exe (Bitdefender ConnectAgent, side-loads log.dll), VSTestVideoRecorder.exe (Microsoft Visual Studio Test component, side-loads Microsoft.VisualStudio.QualityTools.VideoRecorderEngine.dll), and GoogleDesktop.exe (Google Desktop Search, side-loads GoogleServices.dll). Attackers copy the legitimate signed binary and the malicious loader DLL into user-writable locations such as C:\Users\Public\ and C:\windows\vss\, and have been observed persisting via a scheduled task masquerading under the name 'KasperskyEndpointSecurityEDRAvp' to blend in with legitimate Kaspersky endpoint security tooling.

Once running, Umbrij enumerates local Chromium browser profiles (Chrome and Edge) via command-line flags (-regex to match a target email substring, -user to scope to a Windows user, -browser to choose msedge/chrome/both, -deepsearch for verified profile matching, -savepdf to screenshot matched profiles as PDF evidence). For each matched profile it copies profile artifacts needed to reproduce an authenticated browsing context — IndexedDB, Local Storage, Network cache, Login Data, Login Data For Account, Preferences, Secure Preferences, Web Data and the top-level Local State JSON (normally at %LOCALAPPDATA%\Google\Chrome\User Data\Local State) — into a working directory.

Umbrij then launches a hidden/headless instance of the target Chromium browser using the copied profile with the flags --headless and --remote-debugging-port=<port>, and uses the Puppeteer Sharp .NET library to drive the browser over the Chrome DevTools Protocol (CDP). Because the copied profile already contains valid Google authentication cookies, Google treats the automated session as the legitimate, already-authenticated user and does not prompt for re-authentication or MFA. Umbrij programmatically navigates to Google's OAuth2 authorization endpoint (accounts.google.com/o/oauth2/v2/auth) impersonating one of two pre-registered, Google-verified third-party OAuth client applications — 'Google Workspace Migration for Microsoft Outlook' (GWMMO, client ID 279448736670) or, when the -sync flag is used, 'Google Workspace Sync for Microsoft Outlook' (GWSMO, client ID 1095133494869) — and requests broad delegated scopes covering Gmail (mail.google.com), Drive, Calendar, Admin Directory, Contacts and Tasks. Because the session is already authenticated and the OAuth client is a Google-trusted first/third-party integration, Google's consent flow silently issues an authorization code in the redirect URL, which Umbrij intercepts via CDP network inspection and exchanges directly for an OAuth access (and refresh) token via the Google token endpoint — without ever touching the account password, without an interactive consent screen in many enterprise/Workspace configurations, and without generating a traditional 'new sign-in' security alert. Kaspersky has named this technique 'Shadow Token via Remote Debug' (STRD). The resulting access token gives the attacker durable, credential-less API access to the victim's Gmail, Drive, Calendar, Contacts and Tasks data, functioning as a stealthy, non-malware persistence and collection mechanism that survives password resets (until the OAuth grant is explicitly revoked at myaccount.google.com/connections).

Umbrij is assessed as a purpose-built successor/companion to ToddyCat's previously documented email-theft toolset TCSectorCopy (disclosed November 2025), which targeted Microsoft Outlook/M365 access tokens; Umbrij instead pivots the same operational goal — silent, token-based access to a victim's corporate email and cloud productivity data — onto the Google Workspace/Gmail ecosystem. Kaspersky's defensive guidance includes auditing and revoking suspicious third-party OAuth grants (especially GWMMO/GWSMO if not deployed by IT), disabling remote debugging via the Chrome/Edge Group Policy key HKLM\Software\Policies\Google\Chrome\DeveloperToolsAvailability (set to 2), and hunting for browser processes launched with simultaneous --headless and --remote-debugging-port flags.

## MITRE ATT&CK

- T1574 Hijack Execution Flow
- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1550 Use Alternate Authentication Material
- T1550 Use Alternate Authentication Material
- T1134 Access Token Manipulation
- T1134 Access Token Manipulation
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1185 Browser Session Hijacking
- T1005 Data from Local System
- T1114 Email Collection
- T1113 Screen Capture
- T1053 Scheduled Task/Job
- T1053 Scheduled Task/Job
- T1087 Account Discovery
- T1102 Web Service

## Sources

- [How the ToddyCat APT group gains access to Gmail accounts](https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/)
- [ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API](https://thehackernews.com/2026/07/toddycat-linked-umbrij-malware-abuses.html)
- [ToddyCat Uses Shadow Token via Remote Debug to Compromise Gmail Accounts](https://gbhackers.com/toddycat-uses-shadow-token/)
- [ToddyCat APT Automates Gmail Account Compromise With ConfuserEx-Obfuscated .NET Tool](https://cyberpress.org/toddycat-automates-gmail-compromise/)
- [ToddyCat: Unveiling an unknown APT actor attacking high-profile entities in Europe and Asia](https://securelist.com/toddycat/106799/)
- [ToddyCat's New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens](https://thehackernews.com/2025/11/toddycats-new-hacking-tools-steal.html)
- [Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts](https://databreaches.net/2026/06/30/kaspersky-lab-experts-have-discovered-a-new-attack-vector-and-toolkit-for-compromising-corporate-gmail-accounts/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1072
