Overview 31 indicators
ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.
| domain | 29 | G1022-domain.txt |
| ipv4 | 1 | G1022.json |
| url | 1 | G1022.json |
Techniques 25 ATT&CK
Open in ATT&CK Navigator → or download the layer (25 techniques, layer 4.5)
- T1005 Data from Local System
- T1018 Remote System Discovery
- T1021.002 SMB/Windows Admin Shares
- T1036.005 Match Legitimate Resource Name or Location
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1069.002 Domain Groups
- T1074.002 Remote Data Staging
- T1078.002 Domain Accounts
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1095 Non-Application Layer Protocol
- T1106 Native API
- T1190 Exploit Public-Facing Application
- T1518.001 Security Software Discovery
- T1560.001 Archive via Utility
- T1564.003 Hidden Window
- T1566.003 Spearphishing via Service
- T1567.002 Exfiltration to Cloud Storage
- T1680 Local Storage Discovery
- T1686 Disable or Modify System Firewall
Software 9
Principal sources 4 reports
Ranked by how many of this actor's indicators each report brought in.
- 27research.checkpoint.com/2023/stayin-alive-targeted-attacks-agai…
- 27virustotal.com/gui/file/877579185a72fbaf1afa78d3c50dba…
- 3securelist.com/toddycat-keep-calm-and-check-logs/110696
- 1securelist.com/toddycat/106799
Timeline 31 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
research.checkpoint.com/2023/stayin-alive-targeted-attacks-agai… · virustotal.com/gui/file/877579185a72fbaf1afa78d3c50dba…
domain ad.fopingu.com domain admit.pkigoscorp.com domain backend.rtmcsync.com domain cdn.pkigoscorp.com domain cert.qform3d.in domain certexvpn.com domain cyberguard.certexvpn.com domain eaq.machineaccountquota.com domain fopingu.com domain gist.gitbusercontent.com domain git.gitbusercontent.com domain gitbusercontent.com domain idp.pkigoscorp.com domain imap.774b884034c450b.com domain machineaccountquota.com domain ns01.nayatel.orinafz.com domain pic.rtmcsync.com domain pkigoscorp.com domain proxy.rtmcsync.com domain qaq2.machineaccountquota.com domain qform3d.in domain raw.gitbusercontent.com domain rtmcsync.com domain sslvpn.pkigoscorp.com domain update.certexvpn.com ipv4 139.180.145.121:443 url http://139.180.145.121 -
securelist.com/toddycat-keep-calm-and-check-logs/110696
githubdd.workers.dev mfeagents.workers.dev solitary-dawn-61af.mfeagents.workers.dev -
securelist.com/toddycat/106799
eohsdnsaaojrhnqo.windowshost.us