Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ToddyCat

Also known as: Websiic

Description

ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.(Citation: Kaspersky ToddyCat June 2022)(Citation: Kaspersky ToddyCat Check Logs October 2023)

Goals & Targeting

Targeted Sectors

Defense
Government

AI Analysis

· 1 week ago

Executive Summary

ToddyCat (aka Websiic) is a sophisticated cyber threat actor targeting government and military sectors across Europe and Asia since at least 2020. Known for employing custom malware loaders and multi-stage infection chains, ToddyCat has demonstrated high technical skill in compromising sensitive infrastructure through targeted campaigns.

Goals & Targeting

ToddyCat primarily targets government and military sectors, suggesting a focus on espionage, data theft, or disruption of national security infrastructure. The group's targeting strategy appears to be region-agnostic, with operations observed in European and Asian countries. ToddyCat's choice of victims indicates an interest in high-value targets with access to sensitive information, likely aiming to achieve strategic or intelligence gains through their campaigns.

Enhanced Description

ToddyCat is a highly sophisticated cyber threat group that has been actively exploiting government and military targets across Europe and Asia since as early as 2020. The group is known for its use of custom loaders and malware, employing multi-stage infection chains to penetrate target networks. ToddyCat's operations typically involve advanced persistence mechanisms and exfiltration techniques, leveraging tools such as Cobalt Strike and China Chopper for command and control (C2). The group has demonstrated a strong focus on maintaining long-term access to victim networks, often using these footholds to steal sensitive data or disrupt critical systems. Kaspersky reports indicate that ToddyCat's activities have evolved significantly over time, with recent campaigns showing refined tactics such as the use of hidden windows and remote execution frameworks.

Key Capabilities

  • Custom malware loaders
  • Multi-stage infection chains
  • Advanced persistence mechanisms
  • Command and control (C2) frameworks
  • Data exfiltration techniques
  • Network traversal and lateral movement

MITRE ATT&CK Tactics

Defense Evasion
Discovery
Exfiltration
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Collection
Impact

ATT&CK Techniques

T1053.005: Scheduled Task
T1560.001: Archive via Utility
T1566.003: Spearphishing via Service
T1087.002: Domain Account
T1036.005: Match Legitimate Resource Name or Location
T1069.002: Domain Groups
T1074.002: Remote Data Staging
T1005: Data from Local System
T1190: Exploit Public-Facing Application
T1083: File and Directory Discovery
T1049: System Network Connections Discovery
T1059.001: PowerShell
T1567.002: Exfiltration to Cloud Storage
T1078.002: Domain Accounts
T1518.001: Security Software Discovery
T1059.003: Windows Command Shell
T1018: Remote System Discovery
T1686: Disable or Modify System Firewall
T1047: Windows Management Instrumentation
T1106: Native API
T1021.002: SMB/Windows Admin Shares
T1057: Process Discovery
T1095: Non-Application Layer Protocol
T1564.003: Hidden Window
T1680: Local Storage Discovery

Software / Tooling

Ninja
LoFiSe
China Chopper
Cobalt Strike
Samurai
Pcexter

Campaigns & Victims

ToddyCat's campaigns have focused on persistent access to victim networks, with a notable campaign titled 'making holes in your infrastructure.' The group has been observed using tools like Pcexter for backdooring systems and Samurai for lateral movement. Campaign patterns include the use of remote administration tools (RATs) for long-term control, and ToddyCat appears to favor exfiltration via cloud storage services. Notable operations have targeted government websites and military infrastructure across multiple regions.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication over legitimate domains and URLs
  • Staging infrastructure on fast-flux domains
  • Use of custom malware loaders for initial penetration
  • Exfiltration via cloud storage services
  • Scheduled tasks for persistence

Recommended Actions

  • Implement network monitoring for known ToddyCat-related IPs and domains.
  • Secure remote access points with multi-factor authentication (MFA).
  • Segment critical government/military networks from general corporate infrastructure.
  • Deploy endpoint detection and response (EDR) tools to detect advanced persistence frameworks.
  • Train employees on recognizing spear-phishing attempts and suspicious email patterns.
  • Regularly update software and patch known vulnerabilities to mitigate exploitation.

Suggested Tags

APT
espionage
military
government

Confidence Assessment

High confidence in ToddyCat's operational timeline, tools, and targeting patterns based on multiple Kaspersky reports. Some uncertainty remains regarding the group's exact origin and long-term strategic goals, but their level of sophistication suggests a state-sponsored or financially motivated actor.

ATT&CK Techniques

Discovery
8 techniques
Execution
5 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

URL 5 MD5 Hash 7 Domain 1 IPv4 Address 2

References

  1. Kaspersky ToddyCat June 2022 — Dedola, G. (2022, June 21). APT ToddyCat. Retrieved January 3, 2024.
  2. Kaspersky ToddyCat Check Logs October 2023 — Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.

Intel Summary

25

Techniques

7

Tools

1

Campaigns

15

IOCs

0

Observed Data

9

Tactics

Tags

Government Targeting
APT
espionage
military
government

Details

MITRE ID
G1022
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--b516b235-fc7d-4635-aca5-3d33312339c3
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.