The Containment Era is here. →Explore

Executive Summary

Between mid-2024 and early 2025, the ToddyCat advanced persistent threat (APT) group executed a sophisticated campaign targeting organizations' internal infrastructures to covertly access business email. Initially leveraging a new PowerShell variant of their TomBerBil tool to extract credentials, cookies, and encryption keys from browsers via SMB on privileged hosts, the group also introduced additional tools—TCSectorCopy and XstReader—to capture locked Outlook OST files and exfiltrate their contents. When detection increased, ToddyCat shifted to harvesting OAuth 2.0 tokens for Microsoft 365 mail through memory dumping, enhancing their ability to bypass on-host monitoring and access cloud emails externally. This campaign resulted in extensive compromise of sensitive correspondence, credentials, and lateral movement across impacted domains.

This incident underscores the rapidly evolving tactics of nation-state groups to overcome modern defenses, highlighting trends in cross-cloud compromise, credential harvesting, and exploitation of endpoint-to-cloud trust boundaries. ToddyCat's use of both system-level and identity-driven attacks mirrors the increasing prevalence of multifaceted cyber threat techniques.

Why This Matters Now

A surge in identity-centric threats and privilege escalation reinforces the urgent need for organizations to detect lateral movement, credential harvesting, and token theft across hybrid environments. ToddyCat's techniques reflect the broader transition of attackers exploiting both endpoint and cloud weaknesses, directly impacting business resilience and regulatory posture.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach exploited weak lateral movement controls, lack of egress monitoring, insufficient auditing of sensitive file access, and inadequate protections for encryption keys and identity tokens in line with ZTMM, NIST, PCI, and HIPAA frameworks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Deploying CNSF-aligned zero trust controls—such as east-west microsegmentation, centralized visibility, egress policy enforcement, and inline detection—would have contained lateral movement, prevented unauthorized file access, and detected abnormal data collection and exfiltration attempts at multiple kill chain stages.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Rapid detection of anomalous authentication and suspicious access attempts.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits horizontal privilege expansion and unauthorized access to sensitive systems.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Prevents unauthorized SMB and peer-to-peer traffic between workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Comprehensive monitoring and policy enforcement on suspicious application and network behaviors.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents and detects unauthorized exfiltration of sensitive data.

Impact (Mitigations)

Continuously reduces blast radius and enables rapid response to sensitive data exposure.

Impact at a Glance

Affected Business Functions

  • Email Communications
  • Data Security
  • IT Operations
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Unauthorized access to sensitive corporate email communications, including confidential information and potential intellectual property, leading to reputational damage and regulatory scrutiny.

Recommended Actions

  • Enforce zero trust segmentation and east-west traffic controls to block lateral SMB and unauthorized file access within cloud and hybrid workloads.
  • Enable actionable egress security policies to detect and prevent unauthorized data exfiltration over SMB, RDP, and other outbound channels.
  • Implement centralized, real-time visibility and anomaly detection to rapidly identify suspicious authentication, privilege escalation, and use of credential harvesting tools.
  • Harden privileged identities and restrict administrative access using least privilege, MFA, and continuous posture monitoring across multicloud infrastructure.
  • Automate detection and response through Cloud Network Security Fabric, integrating inline enforcement and orchestration to reduce dwell time and remediate threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image