Threats · 74 days ago
ToddyCat has found a way to turn a live browser session into durable Gmail access. Once the session is already logged in, endpoint defenses can miss the real break because the attacker ends up operating through Google API tokens, not by staying on the box.
Kaspersky says the group built a new tool, Umbrij, to connect to Chromium-based browsers through the remote debugging interface, pull an OAuth authorization code from the user’s active Gmail session, and exchange it for an access token. That token then lets the attacker keep reaching corporate mail through the Google API, and Kaspersky published detection guidance and sample hashes for the tool.
The shift matters because the trust boundary has moved into cloud-side tokens and API traffic. If the browser session or OAuth grant is captured, patching the endpoint does not end mailbox access; cloud identity and API monitoring have to catch what endpoint tools no longer see.
2 sources covering this story
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
Kaspersky reports ToddyCat’s Umbrij abuses headless Chromium and OAuth flows to extract Gmail authorization codes, enabling access via tokens.
How the ToddyCat APT group gains access to Gmail accounts
The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.
Part of the PlainSec briefing for 2026-07-02