Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareUsed by 2 actors

TomBerBil

TomBerBil is a ToddyCat-associated credential theft malware family used to steal browser secrets and support access to corporate correspondence in compromised environments. Reported variants have been implemented in C++, C#, and PowerShell. The malware targets browser data protected with Windows DPAPI, including cookies and passwords from Chrome and Edge, by enumerating explorer.exe processes, identifying logged-in users, impersonating those users, extracting the browser master key from the Local State file, and querying Login Data and Cookies SQLite databases. At least one variant masqueraded as Kaspersky software using the filename avpui.exe and Kaspersky-like metadata.

Recent reporting states that intrusions observed between May and June 2024 involved a PowerShell-based TomBerBil variant that copied files containing user encryption keys leveraged by DPAPI and added Mozilla Firefox data extraction capability. This version reportedly ran on domain controllers from a privileged user context and accessed browser files over shared network resources via SMB. The modified TomBerBil family was described as ineffective at evading monitoring tools, which led the threat actor to seek alternative methods for accessing critical data.

TomBerBil is associated with the ToddyCat APT group, which has targeted governmental, defense-related, and other organizations in Asia-Pacific, Europe, and Asia according to the cited reporting. The malware has been used alongside other ToddyCat tooling focused on stealing Outlook data and authentication material. High-confidence behavioral indicators mentioned in the content include user impersonation via explorer.exe token duplication, decryption of DPAPI-protected browser data, extraction of Chrome/Edge cookies and passwords, Firefox data extraction in the PowerShell variant, operation from privileged contexts on domain controllers, SMB-based access to browser files, and masquerading as Kaspersky through avpui.exe.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ToddyCat

This is the exact same mechanism used by another tool in the group’s arsenal, TomBerBil, which we covered previously.

via securelistsecurelist.com
APT ToddyCat

Такую же схему использует и другой инструмент группы — TomBerBil, о котором мы рассказывали ранее.

via securelist rusecurelist.ru
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Privilege Escalation

1 technique
T1134.003Make and Impersonate TokenEvidence2

It searches the system for the explorer.exe process and duplicates its token, retaining all of its privileges (T1134.003 Access Token Manipulation: Make and Impersonate Token).

Stealth

1 technique
T1134.003Make and Impersonate TokenEvidence2

It searches the system for the explorer.exe process and duplicates its token, retaining all of its privileges (T1134.003 Access Token Manipulation: Make and Impersonate Token).

ACTIVITY FEED

Recent activity

6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.