Skip to content
February 8, 2026
Mochiai.blog
Mochiai.blog
Random Article
  • Home
  • Cybersecurity
  • ToddyCat APT evolves to target Outlook archives and Microsoft 365 tokens
Categories Cybersecurity

ToddyCat APT evolves to target Outlook archives and Microsoft 365 tokens

  • By Shweta Sharma
  • Estimated read time 1 min read
  • November 26, 2025
ToddyCat APT evolves to target Outlook archives and Microsoft 365 tokens

While ToddyCat has been active since at least 2020, typically sticking to stealing browser cookies and credentials, this shift toward siphoning entire Outlook archives marks a significant escalation in its playbook. The group previously targeted high-profile organizations in Asia and Europe by hacking into internet-facing Microsoft Exchange servers.

From browsers to domain controllers

In incidents observed between May and June 2024, Kaspersky disclosed detecting a new version of the ToddyCat toolkit “TomBerBill,” written in PowerShell, operating directly from domain controllers under privileged user accounts.

This update expanded the scope of the attack from targeting Chrome and Edge to include Firefox browser data. The script used a scheduled “run” task, created a local directory, and then reached out (over SMB) to connect to user-host directories across the network. Once connected, it copied browser files (cookies, saved credentials, history, etc) for offline analysis.

Tags APT attack ToddyCat malware
← Make.com Automations for Saving Time as a Data Professional → Alliances between ransomware groups tied to recent surge in cybercrime

Loading...

Categories

  • AI Medical
  • AI Reasoning Model
  • Artificial intelligence
  • Best Exam for AI
  • Cybersecurity
  • Machine Learning
  • Programming & Tech
  • Technology
  • Uncategorized
  • VM

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • April 2016

Copyright © 2026
 - Powered by Magze.