databreaches.net 6/30/2026, 5:21:02 PM · external

Kaspersky Warns of ToddyCat Gmail Hack via Shadow Token Technique

CyberSIXT Evidence Panel
Primary Source kaspersky.ru
Threat Actor

KASPERSKY Lab has identified a new method used by the ToddyCat group to compromise corporate Gmail accounts. The attack utilizes a toolkit called Umbrij, which exploits APIs to access user data (emails, calendars, etc.) without the need for login credentials. Attackers gain access through Chromium-based browsers by exploiting saved login sessions. Researchers named this technique Shadow Token via Remote Debug (STRD).

They emphasize the importance of monitoring unusual activities and suggest auditing third-party applications to mitigate risks. Kaspersky Lab highlights the evolving capabilities of the ToddyCat group and stresses that email remains a primary target for attackers.

View Primary Source Via databreaches.net

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline