ToddyCat has found a way to turn a live browser session into durable Gmail access. Once the session is already logged in, endpoint defenses can miss the real break because the attacker ends up operating through Google API tokens, not by staying on the box.
Kaspersky says the group built a new tool, Umbrij, to connect to Chromium-based browsers through the remote debugging interface, pull an OAuth authorization code from the user’s active Gmail session, and exchange it for an access token. That token then lets the attacker keep reaching corporate mail through the Google API, and Kaspersky published detection guidance and sample hashes for the tool.
The shift matters because the trust boundary has moved into cloud-side tokens and API traffic. If the browser session or OAuth grant is captured, patching the endpoint does not end mailbox access; cloud identity and API monitoring have to catch what endpoint tools no longer see.