THREAT_ACTOR · G1022
ToddyCat
Also known as: ToddyCat
Profile
ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.
MITRE ATT&CK ↗Techniques
25 ATT&CK techniques attributed to this actor.
T1005 Data from Local SystemT1018 Remote System DiscoveryT1021.002 SMB/Windows Admin SharesT1036.005 Match Legitimate Resource Name or LocationT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1069.002 Domain GroupsT1074.002 Remote Data StagingT1078.002 Domain AccountsT1083 File and Directory DiscoveryT1087.002 Domain AccountT1095 Non-Application Layer ProtocolT1106 Native APIT1190 Exploit Public-Facing ApplicationT1518.001 Security Software DiscoveryT1560.001 Archive via UtilityT1564.003 Hidden WindowT1566.003 Spearphishing via ServiceT1567.002 Exfiltration to Cloud StorageT1680 Local Storage DiscoveryT1686 Disable or Modify System Firewall
Software
9 malware/tools attributed to this actor.
China ChopperNetPingnetstatCobalt StrikeSamuraiNinjaLoFiSePcexter
Related corpus activity
9,421 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to ToddyCat.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,421.