Umbrij is a .NET-based malware attributed to the ToddyCat APT group, designed to steal OAuth tokens from Gmail accounts. It exploits Chromium-based browsers by launching them in headless mode and connecting via remote debugging ports to hijack active sessions. The malware uses DLL side-loading and is obfuscated with ConfuserEx.