ToddyCat has been innovating its methods to access corporate email data using tools like TCSectorCopy and exploits like CVE-2024-11859. Their tactics include stealing browser credentials, extracting email files, and capturing access tokens, demonstrating evolving cyber espionage techniques. #ToddyCat #TCSectorCopy #CVE-2024-11859 #TomBerBil #SharpTokenFinder
Keypoints
- ToddyCat has developed new methods to breach corporate email systems, including using the TCSectorCopy tool.
- The group targets browsers and email storage, extracting cookies, credentials, and OST files from local and network locations.
- Exploits like CVE-2024-11859 have been used to deliver undocumented malware such as TCESB.
- The threat actors attempt to obtain access tokens from memory using tools like SharpTokenFinder and ProcDump.
- They continuously evolve their tactics to evade detection and maintain persistent access to targeted infrastructures.
Read More: https://thehackernews.com/2025/11/toddycats-new-hacking-tools-steal.html