NEW: Group Profiler — instant APT intel lookup. Try it →

ToddyCat

Overview

ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.

Naming & attribution

ToddyCat is tracked under 1 names across the industry. It uses 25 documented ATT&CK techniques — more than 59% of the 174 groups tracked here. Activity attributed since at least 2020.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Chimera China — 17 shared techniques (25% overlap)
  • menuPass China — 14 shared techniques (25% overlap)
  • Play — 10 shared techniques (24% overlap)
  • APT3 China — 13 shared techniques (23% overlap)
  • Deep Panda China — 6 shared techniques (21% overlap)
  • Ke3chang China — 12 shared techniques (20% overlap)

Targets

Government · Military

Regions

Afghanistan · India · Indonesia · Iran · Kyrgyzstan · Malaysia · Pakistan · Russia · Slovakia · Taiwan · Thailand · United Kingdom · Uzbekistan · Vietnam

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 6 attributed custom malware families

TTPs — 25 techniques across 9 tactics

Tools & malware (9)

Cobalt Strike · LoFiSe · China Chopper · netstat · Ping · Pcexter · Net · Samurai · Ninja

Reporting (2)