


Perceptive Security
SOC/SIEM Consultancy

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens
Published:
25 november 2025 om 11:36:00
Alert date:
5 december 2025 om 08:03:22
Source:
thehackernews.com

The threat actor ToddyCat has been observed using new methods to steal corporate email data, including a custom tool called TCSectorCopy. The attack allows them to obtain OAuth 2.0 authorization protocol tokens using the user's browser, which can be used outside the compromised infrastructure perimeter to access Microsoft 365 services and Outlook emails. This represents an evolution in ToddyCat's tactics to maintain persistence and access to corporate communications.
Technical details
Mitigation steps:
Affected products:
Microsoft Outlook
Microsoft 365
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.