ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens

ToddyCat has been innovating its methods to access corporate email data using tools like TCSectorCopy and exploits like CVE-2024-11859. Their tactics include stealing browser credentials, extracting email files, and capturing access tokens, demonstrating evolving cyber espionage techniques. #ToddyCat #TCSectorCopy #CVE-2024-11859 #TomBerBil #SharpTokenFinder

Keypoints

  • ToddyCat has developed new methods to breach corporate email systems, including using the TCSectorCopy tool.
  • The group targets browsers and email storage, extracting cookies, credentials, and OST files from local and network locations.
  • Exploits like CVE-2024-11859 have been used to deliver undocumented malware such as TCESB.
  • The threat actors attempt to obtain access tokens from memory using tools like SharpTokenFinder and ProcDump.
  • They continuously evolve their tactics to evade detection and maintain persistent access to targeted infrastructures.

Read More: https://thehackernews.com/2025/11/toddycats-new-hacking-tools-steal.html