ToddyCat
Also reported as Websiic and Storm-0247. Linked to China by two sources.
Reports per quarter
Techniques seen in the last two years
- T1005 1 report in ATT&CK
- T1021.002 1 report in ATT&CK
- T1036.005 1 report in ATT&CK
- T1211 1 report reports only
- T1555.003 1 report reports only
- T1560.002 1 report reports only
- T1574 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-5687
- CVE-2013-5947
- CVE-2013-7389
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-2051 KEV
- CVE-2015-7248
- CVE-2017-0144 KEV ransomware
Show all 51 CVEs Show fewer
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2019-0708 KEV ransomware
- CVE-2019-16759 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-17530 KEV
- CVE-2020-2551 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-24085
- CVE-2021-25323
- CVE-2021-25324
- CVE-2021-25325
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30657 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-36276
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-23748 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-34305
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2024-11859
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ShadowPad (Malware Family)
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ToddyCat_ Unveiling an unknown APT actor attacking high-profile entities in Europe and Asia _ Securelist
-
The hateful eight- Kaspersky’s guide to modern ransomware groups’ TTPs (Download Form)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The hateful eight- Kaspersky’s guide to modern ransomware groups’ TTPs (Download Form)
-
APT ToddyCat- Unveiling an unknown APT actor attacking high-profile entities in Europe and Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT ToddyCat- Unveiling an unknown APT actor attacking high-profile entities in Europe and Asia
Show all 20 reports Show fewer
-
Microsoft Exchange servers hacked by new ToddyCat APT gang
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange servers hacked by new ToddyCat APT gang
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12021
-
Exchange servers under siege from at least 10 APT groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exchange servers under siege from at least 10 APT groups
-
Microsoft Exchange Zero Days - Mitigations and Detections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange Zero Days - Mitigations and Detections
Newest first. Details opens the report in Explore.