Saturday, April 19, 2025
HomeCVE/vulnerabilityToddyCat APT Abuses SMB, Exploits IKEEXT A Exchange RCE To Deploy ICMP...

ToddyCat APT Abuses SMB, Exploits IKEEXT A Exchange RCE To Deploy ICMP Backdoor

Published on

SIEM as a Service

Follow Us on Google News

ToddyCat is an APT group that has been active since December 2020, and primarily it targets the government and military entities in Europe and Asia. 

The group is known for its sophisticated cyber-espionage tactics and has been involved in multiple high-profile attacks.

Cybersecurity researchers at Kaspersky Lab identified that ToddyCat APT group has been abusing the SMB, exploiting IKEEXT and Exchange RCE to deploy ICMP backdoor.

- Advertisement - Google News

ToddyCat APT Abuses SMB

In the year 2023, Kaspersky GERT investigated one of the largest internal frauds in a government organization.

Threat actors used an internal service to carry out several fraudulent operations leading to losses of well over 20 million dollars.

Are You From SOC/DFIR Teams? - Try Advanced Malware and Phishing Analysis With ANY.RUN - 14 day free trial

Insider fraud attack (Source – Securelist)

GERT’s digital forensics and incident response (DFIR) analysis revealed multiple attack vectors like:-

  • A vulnerability in a debugging interface that allowed cookie theft for user impersonation, identified through exception logging analysis.
  • Privilege escalation and account manipulation to create fraudulent transactions and obfuscate user details.
  • Unauthorized VPN access from both external and internal networks. 

The team correlated user activities across various systems, including local and remote IDs, to confirm collusion between internal actors. 

This case highlights the critical importance of robust internal controls, privileged access management, and comprehensive logging for detecting and mitigating insider threats in financial systems.

Kaspersky has uncovered a long-standing intrusion in a customer’s infrastructure, revealing a sophisticated attack that had persisted for over 2 years. 

The threat actors apparently belonging to Flax Typhoon APT group, employed living-off-the-land techniques, using SoftEther VPN and Zabbix agent for other purposes than intended.

They sent malware hosted in Windows LOLBins like certutil and disguised services to go undetected.

The attack consisted of NTDS dumping, the usage of Mimikatz and CobaltStrike, specifically creating firewall rules for covert communication.

Due to this finding, the client was able to successfully sue an insider employee and his accomplices responsible for the abuse, which indicates the crucial need for an APT detection solution to confirm and eliminate long-standing threats.

GERT’s assessment matched the timeline of the attack, compromised users, and measures that were used in executing the attack.

The investigation showed SMB abuse, IKEEXT service persistence, and vulnerabilities (CVE-2021-26855) in remote code execution using Microsoft Exchange Servers.

Importantly, a malicious wlbsctrl.dll was used for persistence and lateral movement using the SMB protocol.

Mainly, identified was an ICMP backdoor that was embedded within an application as a loader with mutex checking, registry key manipulation, and execution of encrypted payloads.

ICMP backdoor (Source – Securelist)

The backdoor was implemented using the usual AES method, but the volume serial number of the C drive was one of the key parameters.

Payloads were the last in the stage at which the modules dllhost.exe were injected into, and they were invoked to create a raw ICMP socket, Base64 data reception, and use of encrypted shellcodes.

While the occurrence endured the characteristics of APT group ToddyCat’s TTPs, complete attribution is not evident.

The case highlights the essentiality of general assets availability surveillance, reliance on threat intelligence for protection, and provision of MDR services in all areas.

What Does MITRE ATT&CK Expose About Your Enterprise Security? - Watch Free Webinar!

Tushar Subhra
Tushar Subhra
Tushar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

How SMBs Can Improve SOC Maturity With Limited Resources

Small and Medium-sized Businesses (SMBs) have become prime targets for cybercriminals, being three times...

How To Detect Obfuscated Malware That Evades Static Analysis Tools

Obfuscated malware presents one of the most challenging threats in cybersecurity today. As static...

How Security Analysts Detect and Prevent DNS Tunneling Attack In Enterprise Networks

DNS tunneling represents one of the most sophisticated attack vectors targeting enterprise networks today,...

How to Conduct a Cloud Security Assessment

Cloud adoption has transformed organizations' operations but introduces complex security challenges that demand proactive...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

State Sponsored Hackers now Widely Using ClickFix Attack Technique in Espionage Campaigns

The state-sponsored hackers from North Korea, Iran, and Russia have begunp deploying the ClickFix...

Critical AnythingLLM Vulnerability Exposes Systems to Remote Code Execution

A critical security flaw (CVE-2024-13059) in the open-source AI framework AnythingLLM has raised alarms across cybersecurity...

PoC Released for Linux Kernel Vulnerability Allowing Privilege Escalation

A security vulnerability, tracked as CVE-2024-53141, has recently come to light in the Linux kernel's...