ToddyCat__2022__ToddyCat_Unveiling_an_unknown_APT_actor_attacking_high-profile_entities_in_Europe_and_Asia_Securelist.pdf
ID: adfdd123-e5c8-4109-a61e-000d5bb0fb49
STIX ID: report--adfdd123-e5c8-4109-a61e-000d5bb0fb49
Threat Score
82/100
Uploaded: 2026-08-19
Published Date: 2022-06-27
Last Modified Date: 2022-06-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ToddyCat is a sophisticated APT group targeting high-profile government and military entities in Europe and Asia since December 2020, using a multi-stage infection chain built around Samurai backdoor and Ninja Trojan, with loaders, registry persistence, and a modular .NET backdoor to control compromised systems via HTTP/S C2.
