ToddyCat

Also known as: Storm-0247, Toddy Cat, ToddyCat, Websiic

ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia. Kaspersky ToddyCat June 2022 Kaspersky ToddyCat Check Logs October 2023

🌍 Country China
🧭 ATT&CK G1022
Military Government

Introduction

ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia. Kaspersky ToddyCat June 2022 Kaspersky ToddyCat Check Logs October 2023

Activities and Tactics

Targeted Sectors: Military, Government

Country of Origin: πŸ‡¨πŸ‡³ China

Suspected Victims: Afghanistan, India, Indonesia, Iran, Kyrgyzstan, Malaysia, Pakistan, Russia, Slovakia, Taiwan…

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • Backdoor.Oldrea
  • Trojan.Karagany
  • Unknown Logger
  • Trojan.Mebromi

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

[1] mitre-attack [2] Kaspersky ToddyCat June 2022 Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024. [3] Kaspersky ToddyCat Check Logs October 2023 Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.