Also known as: Websiic
ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.(Citation: Kaspersky ToddyCat June 2022)(Citation: Kaspersky ToddyCat Check Logs October 2023)
Targeted Sectors
Executive Summary
ToddyCat (aka Websiic) is a sophisticated cyber threat actor targeting government and military sectors across Europe and Asia since at least 2020. Known for employing custom malware loaders and multi-stage infection chains, ToddyCat has demonstrated high technical skill in compromising sensitive infrastructure through targeted campaigns.
Goals & Targeting
ToddyCat primarily targets government and military sectors, suggesting a focus on espionage, data theft, or disruption of national security infrastructure. The group's targeting strategy appears to be region-agnostic, with operations observed in European and Asian countries. ToddyCat's choice of victims indicates an interest in high-value targets with access to sensitive information, likely aiming to achieve strategic or intelligence gains through their campaigns.
Enhanced Description
ToddyCat is a highly sophisticated cyber threat group that has been actively exploiting government and military targets across Europe and Asia since as early as 2020. The group is known for its use of custom loaders and malware, employing multi-stage infection chains to penetrate target networks. ToddyCat's operations typically involve advanced persistence mechanisms and exfiltration techniques, leveraging tools such as Cobalt Strike and China Chopper for command and control (C2). The group has demonstrated a strong focus on maintaining long-term access to victim networks, often using these footholds to steal sensitive data or disrupt critical systems. Kaspersky reports indicate that ToddyCat's activities have evolved significantly over time, with recent campaigns showing refined tactics such as the use of hidden windows and remote execution frameworks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ToddyCat's campaigns have focused on persistent access to victim networks, with a notable campaign titled 'making holes in your infrastructure.' The group has been observed using tools like Pcexter for backdooring systems and Samurai for lateral movement. Campaign patterns include the use of remote administration tools (RATs) for long-term control, and ToddyCat appears to favor exfiltration via cloud storage services. Notable operations have targeted government websites and military infrastructure across multiple regions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in ToddyCat's operational timeline, tools, and targeting patterns based on multiple Kaspersky reports. Some uncertainty remains regarding the group's exact origin and long-term strategic goals, but their level of sophistication suggests a state-sponsored or financially motivated actor.
No observed data linked yet.
25
Techniques
7
Tools
1
Campaigns
15
IOCs
0
Observed Data
9
Tactics