ATT&CKGroupsToddyCat

ToddyCat

G1022

Threat group.View on attack.mitre.org

About this group

ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.

Techniques used25

Procedure examples25

TechniqueProcedure example
T1005
Data from Local System

ToddyCat has run scripts to collect documents from targeted hosts.

T1018
Remote System Discovery

ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery.

T1021.002
SMB/Windows Admin Shares

ToddyCat has used locally mounted network shares for lateral movement through targated environments.

T1036.005
Match Legitimate Resource Name or Location

ToddyCat has used the name `debug.exe` for malware components.

T1047
Windows Management Instrumentation

ToddyCat has used WMI to execute scripts for post exploit document collection.

T1049
System Network Connections Discovery

ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts.

T1053.005
Scheduled Task

ToddyCat has used scheduled tasks to execute discovery commands and scripts for collection.

T1057
Process Discovery

ToddyCat has run `cmd /c start /b tasklist` to enumerate processes.

T1059.001
PowerShell

ToddyCat has used Powershell scripts to perform post exploit collection.

T1059.003
Windows Command Shell

ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts.

T1069.002
Domain Groups

ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines.

T1074.002
Remote Data Staging

ToddyCat manually transferred collected files to an exfiltration host using xcopy.

T1078.002
Domain Accounts

ToddyCat has used compromised domain admin credentials to mount local network shares.

T1083
File and Directory Discovery

ToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension.

T1087.002
Domain Account

ToddyCat has run `net user %USER% /dom` for account discovery.

View all 25 procedure examples

Software9

Campaigns0

None recorded.

References2

  1. Kaspersky ToddyCat Check Logs October 2023 Open source
    Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.
  2. Kaspersky ToddyCat June 2022 Open source
    Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.