CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Umbrij Malware: OAuth Token Theft via Headless Browser Exploitation

July 2, 2026

Umbrij is a .NET-based malware attributed to the ToddyCat APT group, designed to steal OAuth tokens from Gmail accounts. It exploits Chromium-based browsers by launching them in headless mode and connecting via remote debugging ports to hijack active sessions. The malware uses DLL side-loading and is obfuscated with ConfuserEx.