CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 35

As cited

Copy frozen at (site build).

threat intel

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

ToddyCat, a known threat actor, has deployed a new malware called Umbrij that abuses OAuth to gain unauthorized access to Gmail accounts through the Google API. The malware targets corporate email communications by compromising API access rather than targeting credentials directly.

Why it matters: Organizations using Gmail for corporate communications face a novel persistence mechanism; security teams should monitor for suspicious OAuth applications and API access patterns in Google Workspace environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

Researchers at Kaspersky report that the ToddyCat threat actor is using a new malware family, Umbrij, to covertly access corporate Gmail accounts through the Google application programming interface (API) by abusing OAuth. The campaign specifically targets business email communications hosted on Gmail.

Why it matters: Organizations using Gmail for corporate email may face unauthorized access to sensitive correspondence via OAuth abuse and should review API permissions and OAuth token usage.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

Researchers at Kaspersky report that the ToddyCat threat actor is using a new malware family, Umbrij, to covertly access corporate Gmail accounts through the Google application programming interface (API) by abusing OAuth. The campaign specifically targets business email communications hosted on Gmail.

Why it matters: Organizations using Gmail for corporate email may face unauthorized access to sensitive correspondence via OAuth abuse and should review API permissions and OAuth token usage.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary