AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
ToddyCat
Aliases: None listed
ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe and Asia.
Open interactive actor investigation
ATT&CK techniques
Data from Local SystemT1069.002
Domain GroupsT1053.005
Scheduled TaskT1566.003
Spearphishing via ServiceT1087.002
Domain AccountT1095
Non-Application Layer ProtocolT1078.002
Domain AccountsT1106
Native APIT1057
Process DiscoveryT1018
Remote System DiscoveryT1562.004
Disable or Modify System FirewallT1049
System Network Connections DiscoveryT1021.002
SMB/Windows Admin SharesT1059.003
Windows Command ShellT1190
Exploit Public-Facing ApplicationT1567.002
Exfiltration to Cloud StorageT1518.001
Security Software DiscoveryT1059.001
PowerShellT1564.003
Hidden WindowT1083
File and Directory DiscoveryT1074.002
Remote Data StagingT1047
Windows Management InstrumentationT1036.005
Match Legitimate Name or LocationT1082
System Information DiscoveryT1560.001
Archive via Utility
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Blue Team & Defensive Security · explicit-idExploitability validation and laboratory exploit engineering
Vulnerability Research & Exploit Development · explicit-idModule 7 — Privilege, lateral movement, and controlled impact
Red Team & Offensive Security · explicit-nameModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · explicit-nameControlled dynamic behavior and differential observation
Malware Analysis & Reverse Engineering · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-nameModule 5 — Threat hunting
Blue Team & Defensive Security · explicit-nameEvidence integrity, order of volatility, and chain of custody
Digital Forensics & Incident Response (DFIR) · topic-matchTimeline reconstruction, ATT CK mapping, CTI, and confidence
Digital Forensics & Incident Response (DFIR) · topic-matchWeakness taxonomy and vulnerability identity
Vulnerability Research & Exploit Development · topic-matchData classification, storage, cryptography, keys, backup, and deletion
Cloud Security · topic-matchCloud logging, detection engineering, ATT CK, and response automation
Cloud Security · topic-match