Threat group.View on attack.mitre.org
ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
ToddyCat has run scripts to collect documents from targeted hosts. |
| T1018 Remote System Discovery |
ToddyCat has used `ping %REMOTE_HOST%` for post exploit discovery. |
| T1021.002 SMB/Windows Admin Shares |
ToddyCat has used locally mounted network shares for lateral movement through targated environments. |
| T1036.005 Match Legitimate Resource Name or Location |
ToddyCat has used the name `debug.exe` for malware components. |
| T1047 Windows Management Instrumentation |
ToddyCat has used WMI to execute scripts for post exploit document collection. |
| T1049 System Network Connections Discovery |
ToddyCat has used `netstat -anop tcp` to discover TCP connections to compromised hosts. |
| T1053.005 Scheduled Task |
ToddyCat has used scheduled tasks to execute discovery commands and scripts for collection. |
| T1057 Process Discovery |
ToddyCat has run `cmd /c start /b tasklist` to enumerate processes. |
| T1059.001 PowerShell |
ToddyCat has used Powershell scripts to perform post exploit collection. |
| T1059.003 Windows Command Shell |
ToddyCat has used .bat scripts and `cmd` for execution on compromised hosts. |
| T1069.002 Domain Groups |
ToddyCat has executed `net group "domain admins" /dom` for discovery on compromised machines. |
| T1074.002 Remote Data Staging |
ToddyCat manually transferred collected files to an exfiltration host using xcopy. |
| T1078.002 Domain Accounts |
ToddyCat has used compromised domain admin credentials to mount local network shares. |
| T1083 File and Directory Discovery |
ToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension. |
| T1087.002 Domain Account |
ToddyCat has run `net user %USER% /dom` for account discovery. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.