ToddyCat APT Hijacks Corporate Gmail via OAuth Token Theft Through Browser Debugging Ports
The ToddyCat APT group's Umbrij tool exploits a legitimate browser feature — remote debugging ports — to intercept OAuth 2.0 authorization codes and silently acquire access tokens for corporate Gmail accounts. This attack bypasses traditional security controls because it abuses a trusted protocol (OAuth 2.0) rather than exploiting a software vulnerability, making it difficult for standard security solutions to detect. The root issue lies in misconfigured or unnecessarily enabled browser remote debugging capabilities combined with insufficient monitoring of OAuth token issuance and usage. This matters because once attackers hold valid access tokens, they gain persistent, authenticated access to sensitive email communications without needing credentials or triggering password-based alerts. Organizations relying solely on MFA for email protection may find it ineffective against token-theft techniques like this.
Tactical Insight
Immediate actions
- Disable Chrome/browser remote debugging ports (e.g., `--remote-debugging-port`) via Group Policy or endpoint management on all corporate devices.
- Audit all active OAuth 2.0 tokens and third-party app authorizations in Google Workspace and revoke any unrecognized or suspicious grants.
- Enable Google Workspace alert policies for anomalous OAuth token activity and suspicious login locations.
Long-term improvements
- Enforce application allowlisting to prevent unauthorized tools (such as Umbrij) from executing on corporate endpoints.
- Implement a least-privilege OAuth scope policy, restricting third-party and internal apps to only the Google API scopes they explicitly require.
- Adopt a zero-trust endpoint posture where browser process behavior is continuously validated and abnormal inter-process communication is blocked.
Detection measures
- Deploy EDR rules to detect processes attempting to connect to local browser debugging ports (e.g., TCP 9222) on corporate machines.
- Monitor Google Workspace audit logs for OAuth token issuance events outside of approved applications and flag tokens issued to unrecognized client IDs.
- Set up SIEM correlation rules to alert when email access patterns deviate significantly from a user's baseline (e.g., bulk read from new IP or user-agent).