CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Umbrij

tool · tool:toddycat-umbrij-oauth-token-theft-strd single-source

ToddyCat tool for OAuth-token theft via Chromium remote debugging (STRD).

Coverage
1
first 2026-07-01 → last 2026-07-01
Latest activity
2026-07-01
Kaspersky GReAT: ToddyCat's "Umbrij" automates Gmail/Workspace OAuth-token theft via Chromium…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, defense
Sources cited
1
1 hosts

Story timeline

  1. 2026-07-01Kaspersky GReAT: ToddyCat's "Umbrij" automates Gmail/Workspace OAuth-token theft via Chromium remote-debugging abuse
    research
ATT&CK techniques (3 across 4 tactics)

3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ExecutionHijack Execution Flow: DLL
  • Privilege EscalationAccess Token Manipulation: Make and Impersonate Token
  • StealthAccess Token Manipulation: Make and Impersonate Token · Hijack Execution Flow: DLL
  • Lateral MovementUse Alternate Authentication Material: Application Access Token

Execution TA0002

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace · ATT&CK page ↗

Privilege Escalation TA0004

T1134.003Access Token Manipulation: Make and Impersonate Token×1

Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the `LogonUser` function. The function will return a copy of the new session's access token and the adversary can use `SetThreadToken` to assign the token to a thread.

Evidence: 2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace · ATT&CK page ↗

Stealth TA0005

T1134.003Access Token Manipulation: Make and Impersonate Token×1

Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username and password but the user is not logged onto the system the adversary can then create a logon session for the user using the `LogonUser` function. The function will return a copy of the new session's access token and the adversary can use `SetThreadToken` to assign the token to a thread.

Evidence: 2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace · ATT&CK page ↗

Lateral Movement TA0008

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace · ATT&CK page ↗

Entries about Umbrij (1)

2026-07-01 · view entry permalink →

NOTABLE

Kaspersky GReAT: ToddyCat's "Umbrij" automates Gmail/Workspace OAuth-token theft via Chromium remote-debugging abuse

Kaspersky GReAT documented Umbrij, a .NET tool used by the ToddyCat APT that automates theft of Google Workspace OAuth tokens through a technique GReAT calls Shadow Token via Remote Debug (STRD) (Kaspersky Securelist, 2026-06-30). Umbrij copies the victim's existing Chromium profile (cached credentials, session cookies), relaunches the browser headless with the DevTools remote-debugging port enabled, and drives it via Puppeteer Sharp to silently replay a legitimate OAuth authorization-code flow against Google APIs, extracting the authorization code with no user interaction, then exchanging it server-side for access/refresh tokens. The requested scopes include https://mail.google.com/ and https://www.googleapis.com/auth/gmail.insert. Prerequisites are on-host code execution plus an already-authenticated Gmail/Workspace browser session; no separate phishing step. Umbrij loads via DLL search-order hijacking (T1574.001) through signed legitimate binaries, BDSubWiz.exe (a Bitdefender ConnectAgent component, loading log.dll), VSTestVideoRecorder.exe (a Visual Studio testing tool), and the discontinued GoogleDesktop.exe (loading GoogleServices.dll). Because it operates inside a standard browser-automation framework rather than touching credential stores directly, it evades detection tuned to credential-store access; Securelist maps the access-token stages to T1550.001 (Use Application Access Token) and T1134.003 (Access Token Manipulation: Make and Impersonate Token). [SINGLE-SOURCE]; Kaspersky is the sole publisher. Detection concepts: alert on Chromium/Edge launched with --remote-debugging-port (and --headless) from non-browser parents such as BDSubWiz.exe, VSTestVideoRecorder.exe or GoogleDesktop.exe; watch Workspace admin logs for OAuth token issuance to unexpected client IDs. Hardening: enforce Chrome Enterprise DeveloperToolsAvailability=Disabled where remote debugging isn't needed, and review OAuth app grants.

research01 Jul 04:41Zsingle-sourceOpen finding →

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • securelist.com1 (100%)