Umbrij Malware Hijacks OAuth Tokens via Browser Debug Ports to Steal Gmail Data
The ToddyCat APT group's Umbrij malware exploits a dangerous combination of OAuth 2.0 token theft and Chromium's remote debugging ports to silently access corporate Gmail accounts without needing credentials. By harvesting active session tokens from the browser, attackers bypass multi-factor authentication entirely, since the token already represents an authenticated session. DLL side-loading and obfuscation allow the malware to persist and evade detection while exfiltrating sensitive email communications. This attack highlights that even well-designed authentication protocols like OAuth 2.0 can be weaponized when endpoint security and browser configurations are not properly hardened. Organizations relying on cloud productivity suites must treat browser session integrity as a critical security boundary.
Tactical Insight
Immediate actions
- Disable or restrict Chromium remote debugging ports (e.g., `--remote-debugging-port`) via Group Policy or endpoint management tools across all corporate devices.
- Audit and revoke suspicious OAuth application authorizations in Google Workspace Admin Console, especially those granted by unrecognized third-party apps.
- Deploy endpoint detection and response (EDR) tools configured to alert on DLL side-loading patterns and unauthorized Google API token requests.
Long-term improvements
- Enforce OAuth application allowlisting in Google Workspace so only pre-approved applications can request access tokens for corporate Gmail accounts.
- Implement application control policies to prevent unauthorized DLL injection and side-loading techniques on all corporate endpoints.
- Adopt a Zero Trust architecture that continuously validates session legitimacy, not just initial authentication, for cloud service access.
Detection measures
- Monitor Google Workspace audit logs for anomalous OAuth token grants, unusual API access patterns, or Gmail access from unexpected locations or applications.
- Configure SIEM rules to detect Chromium processes spawned with remote debugging flags or unexpected child processes associated with browser executables.
- Establish threat hunting routines targeting ToddyCat TTPs using indicators published by Kaspersky and cross-referenced with MITRE ATT&CK techniques (T1185, T1550.001).