Executive Summary
In June 2026, the advanced persistent threat group known as ToddyCat deployed a new malware tool named Umbrij to infiltrate corporate Gmail accounts. Utilizing a technique termed Shadow Token via Remote Debug (STRD), the attackers exploited active user sessions in Chromium-based browsers to obtain OAuth tokens, granting unauthorized access to Gmail and other Google services without requiring user credentials. This method allowed them to read emails, access calendars, and gather data from Google Drive, all while remaining undetected for extended periods.
The emergence of Umbrij underscores a significant evolution in cyber-espionage tactics, highlighting the increasing sophistication of threat actors in bypassing traditional security measures. Organizations must reassess their security protocols, particularly concerning API access and browser session management, to mitigate such advanced threats.
Why This Matters Now
The deployment of Umbrij by ToddyCat represents a critical shift in cyber-espionage tactics, emphasizing the need for organizations to enhance their security measures against sophisticated API exploitation and session hijacking techniques.
Attack Path Analysis
The ToddyCat APT group deployed the Umbrij malware to gain unauthorized access to corporate Gmail accounts by exploiting OAuth tokens. They initiated the attack by delivering a digitally signed file that, through DLL side-loading, launched Umbrij. The malware then escalated privileges by duplicating the token of the 'explorer.exe' process to inherit the logged-in user's privileges. Utilizing this elevated access, Umbrij launched a headless browser session to interact with an active Gmail session, obtaining an OAuth authorization code. This code was exchanged for an access token, allowing the attackers to access Gmail data via the Google API. The exfiltrated data included emails, contacts, and calendar information, compromising corporate communications.
Kill Chain Progression
Initial Compromise
Description
The attackers delivered a digitally signed file that, through DLL side-loading, launched the Umbrij malware on the target system.
MITRE ATT&CK® Techniques
Steal Application Access Token
Use Alternate Authentication Material: Application Access Token
Cloud Application Integration
Account Discovery: Email Account
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and software vulnerabilities are defined, documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication and authorization mechanisms.
Control ID: Identity Pillar: Authentication and Authorization
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
ToddyCat's Umbrij malware targeting Gmail APIs poses critical risks to financial communications, potentially compromising encrypted transactions and regulatory compliance requirements.
Legal Services
Attorney-client privileged communications via Gmail face severe confidentiality breaches from OAuth-abusing infostealer malware, violating professional ethics and client trust.
Health Care / Life Sciences
Healthcare organizations using Gmail for patient communications risk HIPAA violations and PHI exposure through API-based email compromise and data exfiltration.
Government Administration
Government agencies face national security risks from corporate email compromise, with potential classified information exposure through Google API abuse and lateral movement.
Sources
- ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google APIhttps://thehackernews.com/2026/07/toddycat-linked-umbrij-malware-abuses.htmlVerified
- Kaspersky Lab has identified a tool that allows attackers to access corporate emails in Gmailhttps://www.kaspersky.ru/about/press-releases/netajnye-perepiski-laboratoriya-kasperskogo-vyyavila-instrument-pozvolyayushij-zloumyshlennikam-poluchat-dostup-k-korporativnoj-pochte-v-gmailVerified
- ToddyCat APT Deploys 'Umbrij' Tool for Shadow Token via Remote Debug (STRD) Attackshttps://qpulse.quasarcybertech.com/news/4415/toddycat-apt-deploys-umbrij-tool-for-shadow-token-via-remote-debug-strd-attacksVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to exploit OAuth tokens and access corporate Gmail accounts by enforcing strict segmentation and identity-aware routing.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely limit the malware's ability to communicate with unauthorized systems, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the malware's ability to access sensitive resources by enforcing strict access controls.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the potential for lateral movement by enforcing strict segmentation between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit unauthorized command and control communications by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit unauthorized data exfiltration by enforcing strict outbound traffic policies.
The implementation of CNSF controls would likely limit the scope of data breaches by containing the attacker's access to a minimal set of resources.
Impact at a Glance
Affected Business Functions
- Email Communications
- Calendar Management
- Contact Management
- Document Storage
Estimated downtime: N/A
Estimated loss: N/A
Potential unauthorized access to corporate emails, calendars, contacts, and documents stored in Google Workspace.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict malware from accessing sensitive applications and data.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to unauthorized access attempts.
- • Utilize Multicloud Visibility & Control to monitor and manage access across cloud services.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Regularly review and revoke unnecessary OAuth tokens and application permissions to minimize attack surfaces.



