ToddyCat is a threat actor of unknown origin targeting military and government sectors since December 2020.
Analyst brief
ToddyCat (also tracked as Websiic) is a threat actor of unknown origin active since December 2020. It primarily targets military and government sectors across multiple countries in Europe and Asia. The actor uses 'Exploit Public-Facing Application' and 'Spearphishing via Service' for initial access, followed by 'Scheduled Task' for execution, and leverages 'SMB/Windows Admin Shares' for lateral movement, ultimately exfiltrating data to cloud storage. Defenders should focus on detecting 'Cobalt Strike', the custom 'Samurai backdoor' and 'Ninja Trojan', along with patching public-facing applications and closely monitoring domain account usage.
ToddyCat
Websiic
unknown
ToddyCat is responsible for multiple sets of attacks detected since December 2020 against high-profile entities in Europe and Asia. There is still little information about this actor, but its main distinctive signs are two formerly unknown tools that Kaspersky call ‘Samurai backdoor’ and ‘Ninja Trojan’.