VMTech
Discuss a project

ToddyCat and Umbrij: APT Steals Gmail Access via OAuth and Browser Sessions

ToddyCat and Umbrij: APT Steals Gmail Access via OAuth and Browser Sessions

Colleagues, a cybersecurity case: ToddyCat is using Umbrij to access Gmail via the Google API.

The attack relies on an OAuth token and an active Chromium session. The browser runs headless, uses an authenticated profile, and gains email access without a password.

DLL sideloading and masquerading as legitimate processes have also been observed, complicating detection.

What you can do now: review permissions granted to Google accounts and revoke unnecessary access, especially for Microsoft Outlook migration and synchronization apps.

Why it matters: a single compromised token can open access to corporate correspondence and related services.

Do you already control OAuth access in your company?

#cybersecurity #OAuth #Gmail #APT

Open analytics
On the site 3 views
min read 1 04.07.2026
Instagram

ToddyCat and Umbrij: APT Steals Gmail Access via OAuth and Browser Sessions

Open the post on Instagram ↗