{"id":102581,"date":"2022-06-24T06:44:43","date_gmt":"2022-06-24T06:44:43","guid":{"rendered":"https:\/\/www.stellarinfo.com\/blog\/?p=102581"},"modified":"2023-07-20T06:55:28","modified_gmt":"2023-07-20T06:55:28","slug":"toddycat-apt-gang-targeting-microsoft-exchange-servers","status":"publish","type":"post","link":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/","title":{"rendered":"New ToddyCat APT Gang Targeting Microsoft Exchange Servers"},"content":{"rendered":"<?xml encoding=\"utf-8\" ?><?xml encoding=\"utf-8\" ?><p><strong>ToddyCat<\/strong>, an Advanced Persistent Threat (APT) gang,has been targeting and exploiting vulnerable Exchange Servers throughout Europe and Asia since December 2020. Between December 2020 and February 2021, the gang targeted and attacked a limited number of entities in Vietnam and Taiwan. The gang exclusively attacked Exchange Servers previously compromised with Samurai &mdash; an advanced passive backdoor that works on 443 and 80 ports.<\/p><p>They used the malware to execute arbitrary code and multiple modules to remotely administer, control, and move laterally into the targeted network. In some cases, the Samurai backdoor was also used to run another sophisticated Trojan cum loader called Ninja. They also used the China Chopper, a 4 KB web shell, to get access to the server and download and execute another dropper.<\/p><p>However, the ToddyCat APT gang started attacking more servers between February 2021 and May 2021. During this wave of attacks, the gang exploited the infamous <strong>ProxyLogon<\/strong> RCE vulnerability in the unpatched Exchange Servers. This time the gang targeted many prominent countries, including Russia, Afghanistan, India, Iran, Malaysia, Pakistan, Slovakia, Thailand, and United Kingdom.<\/p><p>In the next wave of attacks &mdash; until February 2023 &mdash; the ToddyCat gang increased the scope of attacks and targeted organizations in Indonesia, Kyrgyzstan, and Uzbekistan, in addition to the previously targeted countries.<\/p><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/toddycat-apt-trageting-exchnage-servers.png\" alt=\"toddycat apt trageting exchnage servers\" class=\"wp-image-102585 apply-gradient-on-post-images\" srcset=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/toddycat-apt-trageting-exchnage-servers.png 1024w, https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/toddycat-apt-trageting-exchnage-servers-300x169.png 300w, https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/toddycat-apt-trageting-exchnage-servers-768x432.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Image Source &ndash; ToddyCat attack waves (Kaspersky)<\/figcaption><\/figure><h2 class=\"wp-block-heading\" id=\"how-to-protect-your-exchange-server-environment-from-toddycat?\">How to Protect your Exchange Server Environment from ToddyCat?<\/h2><p>To protect and safeguard your Exchange Server and network infrastructure from ToddyCat or ransomware attacks, install the latest Cumulative Updates and Security Updates on your Exchange Server to patch the vulnerabilities. Also, consider upgrading to the latest version, if your organization is using an older Exchange Server version.<\/p><p>In addition, follow the below steps to check your server health and detect vulnerabilities.&nbsp;<\/p><h3 class=\"wp-block-heading\" id=\"h-step-1-run-msert-scan\">Step 1: Run MSERT Scan<\/h3><p>The Microsoft Safety Scanner or MSERT tool scans servers for any malware or web shells installed on your Windows Server environment and removes them from the system. Here&rsquo;s how to use it:<\/p><ul class=\"wp-block-list\">\n<li>Download the Microsoft Safety Scanner and then open it.<\/li>\n\n\n\n<li>Accept the terms and click<strong> Next &gt; Next<\/strong>.<\/li>\n\n\n\n<li>Select the Scan type and click <strong>Next<\/strong> to start the scan.<\/li>\n<\/ul><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"455\" height=\"409\" src=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/run-quick-scan-using-MSERt.png\" alt=\"run quick scan using MSERt\" class=\"wp-image-102586 apply-gradient-on-post-images\" srcset=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/run-quick-scan-using-MSERt.png 455w, https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/run-quick-scan-using-MSERt-300x270.png 300w\" sizes=\"auto, (max-width: 455px) 100vw, 455px\" \/><\/figure><ul class=\"wp-block-list\">\n<li>Based on the scan type, this may take a while to complete<\/li>\n<\/ul><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"455\" height=\"411\" src=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/running-amlware-scan-using-MSERT.png\" alt=\"running malware scan using MSERT\" class=\"wp-image-102587 apply-gradient-on-post-images\" srcset=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/running-amlware-scan-using-MSERT.png 455w, https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/running-amlware-scan-using-MSERT-300x271.png 300w\" sizes=\"auto, (max-width: 455px) 100vw, 455px\" \/><\/figure><ul class=\"wp-block-list\">\n<li>The results are logged and stored<strong> <\/strong>at <strong>%SYSTEMROOT%\\debug\\msert.log<\/strong>.<\/li>\n<\/ul><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"878\" height=\"453\" src=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/check-MSERT-logs.png\" alt=\"check MSERT logs\" class=\"wp-image-102588 apply-gradient-on-post-images\" srcset=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/check-MSERT-logs.png 878w, https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/check-MSERT-logs-300x155.png 300w, https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/check-MSERT-logs-768x396.png 768w\" sizes=\"auto, (max-width: 878px) 100vw, 878px\" \/><\/figure><h3 class=\"wp-block-heading\" id=\"h-step-2-use-health-checker-powershell-script\">Step 2: Use Health Checker PowerShell Script<\/h3><p>You can download the HealthChecker.ps1 script from the official GitHub page and follow the steps below to execute it on your Microsoft Exchange Server 2013, 2016, or 2019. The script helps you check the server&rsquo;s health, detect vulnerabilities, and patch them. Follow these steps:<\/p><ul class=\"wp-block-list\">\n<li>Launch the Exchange Management Shell (EMS) and run the following command. This will allow you to execute the HealthChecker.ps1 script without error.<\/li>\n<\/ul><pre class=\"wp-block-preformatted\">Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass<\/pre><ul class=\"wp-block-list\">\n<li>Navigate to the folder location where the HealthChecker.ps1 script is located using the &lsquo;<strong>cd&rsquo;<\/strong> command in the EMS. For instance,<\/li>\n<\/ul><pre class=\"wp-block-preformatted\"><strong>cd C:\\Users\\YourUserName\\Downloads\\<\/strong><strong><\/strong><\/pre><ul class=\"wp-block-list\">\n<li>Then execute the following command to run the HealthChecker.ps1 script on your Microsoft Exchange Server.<\/li>\n<\/ul><pre class=\"wp-block-preformatted\"><strong>.\\HealthChecker.ps1 &ndash;BuildHtmlServersReport<\/strong><\/pre><ul class=\"wp-block-list\">\n<li>This will generate a detailed report in an HTML file. The file is saved in the same folder where the HealthChecker.ps1 script is located.<\/li>\n\n\n\n<li>Double-click on the HTML report file to open it in a web browser, such as Google Chrome or Microsoft Edge.<\/li>\n<\/ul><figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"826\" src=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/healthchecker-script-html-report.png\" alt=\"healthchecker script html report\" class=\"wp-image-102589 apply-gradient-on-post-images\" srcset=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/healthchecker-script-html-report.png 1024w, https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/healthchecker-script-html-report-300x242.png 300w, https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/healthchecker-script-html-report-768x620.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><ul class=\"wp-block-list\">\n<li>Check and fix the issues highlighted with <strong>Red<\/strong>.<\/li>\n\n\n\n<li>In the end, check the vulnerabilities section. Then, use the links to download the updates and install them on your server.<\/li>\n<\/ul><p>You can follow our detailed guide to&nbsp;<a href=\"https:\/\/www.stellarinfo.com\/article\/install-exchange-cumulative-updates.php\" target=\"_blank\" rel=\"noreferrer noopener\">download and install the latest Exchange Server Updates<\/a>.<\/p><h2 class=\"wp-block-heading\" id=\"conclusion\">Conclusion<\/h2><p>ToddyCat is not a new but lesser-known APT gang that has been targeting Microsoft Exchange Servers since December 2020. It&rsquo;s a sophisticated APT gang that uses various techniques to stay low profile and avoid detection. They target previously compromised or vulnerable and unpatched Microsoft Exchange Servers to steal or encrypt data for a ransom. It has affected government and private entities, including the military, mostly in Asia and Europe. The best defense against ToddyCat or ransomware groups is to install the latest Cumulative and Security Updates released by Microsoft as soon as possible. However, if your server is compromised or crashed due to ToddyCat or any other malicious attack, it is recommended that you set up a new server and restore the mailbox databases from the backup or use Exchange recovery software, such as&nbsp;<a href=\"https:\/\/www.stellarinfo.com\/edb-exchange-server-recovery.htm\" target=\"_blank\" rel=\"noreferrer noopener\">Stellar Repair for Exchange<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ToddyCat, an Advanced Persistent Threat (APT) gang,has been targeting and exploiting vulnerable&hellip; <a class=\"more-link\" href=\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/\">Continue reading <span class=\"screen-reader-text\">New ToddyCat APT Gang Targeting Microsoft Exchange Servers<\/span><\/a><\/p>\n","protected":false},"author":32,"featured_media":102650,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5298],"tags":[],"class_list":["post-102581","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ransomware","entry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New ToddyCat APT Gang Targeting Microsoft Exchange Servers | Stellar<\/title>\n<meta name=\"description\" content=\"Learn how ToddyCat exploits the Exchange Servers and the steps to protect your Exchange Servers and networks from such sophisticated attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New ToddyCat APT Gang Targeting Microsoft Exchange Servers | Stellar\" \/>\n<meta property=\"og:description\" content=\"Learn how ToddyCat exploits the Exchange Servers and the steps to protect your Exchange Servers and networks from such sophisticated attacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/\" \/>\n<meta property=\"og:site_name\" content=\"Stellar Data Recovery Blog\" \/>\n<meta property=\"article:author\" content=\"https:\/\/facebook.com\/raavisingh\" \/>\n<meta property=\"article:published_time\" content=\"2022-06-24T06:44:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-07-20T06:55:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ravi Singh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/ravi51ngh\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ravi Singh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/\"},\"author\":{\"name\":\"Ravi Singh\",\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/#\/schema\/person\/7dea10d15c0307370e21d7da07d0cd11\"},\"headline\":\"New ToddyCat APT Gang Targeting Microsoft Exchange Servers\",\"datePublished\":\"2022-06-24T06:44:43+00:00\",\"dateModified\":\"2023-07-20T06:55:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/\"},\"wordCount\":716,\"image\":{\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg\",\"articleSection\":[\"Ransomware\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/\",\"url\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/\",\"name\":\"New ToddyCat APT Gang Targeting Microsoft Exchange Servers | Stellar\",\"isPartOf\":{\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg\",\"datePublished\":\"2022-06-24T06:44:43+00:00\",\"dateModified\":\"2023-07-20T06:55:28+00:00\",\"author\":{\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/#\/schema\/person\/7dea10d15c0307370e21d7da07d0cd11\"},\"description\":\"Learn how ToddyCat exploits the Exchange Servers and the steps to protect your Exchange Servers and networks from such sophisticated attacks.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#primaryimage\",\"url\":\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg\",\"contentUrl\":\"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg\",\"width\":1000,\"height\":600,\"caption\":\"Stellar Data Recovery\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.stellarinfo.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New ToddyCat APT Gang Targeting Microsoft Exchange Servers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/#website\",\"url\":\"https:\/\/www.stellarinfo.com\/blog\/\",\"name\":\"Stellar Data Recovery Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.stellarinfo.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/#\/schema\/person\/7dea10d15c0307370e21d7da07d0cd11\",\"name\":\"Ravi Singh\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.stellarinfo.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/9e95cad83fe279b559794f62193f34300d01db8f9f2ec45ce529b7ecde3796ba?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/9e95cad83fe279b559794f62193f34300d01db8f9f2ec45ce529b7ecde3796ba?s=96&d=mm&r=g\",\"caption\":\"Ravi Singh\"},\"description\":\"Ravi Singh is a Senior Writer at Stellar\u00ae. He is an expert Tech Explainer, IoT enthusiast, and a passionate nerd with over 7 years of experience in technical writing. He writes about Microsoft Exchange, Microsoft 365, Email Migration, Linux, Windows, Mac, DIY Tech, and Smart Home. Ravi spends most of his weekends working with IoT (DIY Smart Home) devices and playing Overwatch. He is also a solo traveler who loves hiking and exploring new trails.\",\"sameAs\":[\"https:\/\/stellarinfo.com\/blog\",\"https:\/\/facebook.com\/raavisingh\",\"https:\/\/instagram.com\/ravi.s1ngh\",\"https:\/\/linkedin.com\/in\/ravi-singh-5a65356a\/\",\"https:\/\/x.com\/https:\/\/twitter.com\/ravi51ngh\",\"https:\/\/youtube.com\/ravisingh9\"],\"url\":\"https:\/\/www.stellarinfo.com\/blog\/author\/ravi\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New ToddyCat APT Gang Targeting Microsoft Exchange Servers | Stellar","description":"Learn how ToddyCat exploits the Exchange Servers and the steps to protect your Exchange Servers and networks from such sophisticated attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/","og_locale":"en_US","og_type":"article","og_title":"New ToddyCat APT Gang Targeting Microsoft Exchange Servers | Stellar","og_description":"Learn how ToddyCat exploits the Exchange Servers and the steps to protect your Exchange Servers and networks from such sophisticated attacks.","og_url":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/","og_site_name":"Stellar Data Recovery Blog","article_author":"https:\/\/facebook.com\/raavisingh","article_published_time":"2022-06-24T06:44:43+00:00","article_modified_time":"2023-07-20T06:55:28+00:00","og_image":[{"width":1000,"height":600,"url":"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg","type":"image\/jpeg"}],"author":"Ravi Singh","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/ravi51ngh","twitter_misc":{"Written by":"Ravi Singh","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#article","isPartOf":{"@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/"},"author":{"name":"Ravi Singh","@id":"https:\/\/www.stellarinfo.com\/blog\/#\/schema\/person\/7dea10d15c0307370e21d7da07d0cd11"},"headline":"New ToddyCat APT Gang Targeting Microsoft Exchange Servers","datePublished":"2022-06-24T06:44:43+00:00","dateModified":"2023-07-20T06:55:28+00:00","mainEntityOfPage":{"@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/"},"wordCount":716,"image":{"@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg","articleSection":["Ransomware"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/","url":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/","name":"New ToddyCat APT Gang Targeting Microsoft Exchange Servers | Stellar","isPartOf":{"@id":"https:\/\/www.stellarinfo.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#primaryimage"},"image":{"@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg","datePublished":"2022-06-24T06:44:43+00:00","dateModified":"2023-07-20T06:55:28+00:00","author":{"@id":"https:\/\/www.stellarinfo.com\/blog\/#\/schema\/person\/7dea10d15c0307370e21d7da07d0cd11"},"description":"Learn how ToddyCat exploits the Exchange Servers and the steps to protect your Exchange Servers and networks from such sophisticated attacks.","breadcrumb":{"@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#primaryimage","url":"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg","contentUrl":"https:\/\/www.stellarinfo.com\/blog\/wp-content\/uploads\/2022\/06\/Microsoft-Exchange-Servers-Hacked-By-New-ToddyCat-APT-Gang.jpg","width":1000,"height":600,"caption":"Stellar Data Recovery"},{"@type":"BreadcrumbList","@id":"https:\/\/www.stellarinfo.com\/blog\/toddycat-apt-gang-targeting-microsoft-exchange-servers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.stellarinfo.com\/blog\/"},{"@type":"ListItem","position":2,"name":"New ToddyCat APT Gang Targeting Microsoft Exchange Servers"}]},{"@type":"WebSite","@id":"https:\/\/www.stellarinfo.com\/blog\/#website","url":"https:\/\/www.stellarinfo.com\/blog\/","name":"Stellar Data Recovery Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.stellarinfo.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.stellarinfo.com\/blog\/#\/schema\/person\/7dea10d15c0307370e21d7da07d0cd11","name":"Ravi Singh","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.stellarinfo.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/9e95cad83fe279b559794f62193f34300d01db8f9f2ec45ce529b7ecde3796ba?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e95cad83fe279b559794f62193f34300d01db8f9f2ec45ce529b7ecde3796ba?s=96&d=mm&r=g","caption":"Ravi Singh"},"description":"Ravi Singh is a Senior Writer at Stellar\u00ae. He is an expert Tech Explainer, IoT enthusiast, and a passionate nerd with over 7 years of experience in technical writing. He writes about Microsoft Exchange, Microsoft 365, Email Migration, Linux, Windows, Mac, DIY Tech, and Smart Home. Ravi spends most of his weekends working with IoT (DIY Smart Home) devices and playing Overwatch. He is also a solo traveler who loves hiking and exploring new trails.","sameAs":["https:\/\/stellarinfo.com\/blog","https:\/\/facebook.com\/raavisingh","https:\/\/instagram.com\/ravi.s1ngh","https:\/\/linkedin.com\/in\/ravi-singh-5a65356a\/","https:\/\/x.com\/https:\/\/twitter.com\/ravi51ngh","https:\/\/youtube.com\/ravisingh9"],"url":"https:\/\/www.stellarinfo.com\/blog\/author\/ravi\/"}]}},"_links":{"self":[{"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/posts\/102581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/users\/32"}],"replies":[{"embeddable":true,"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/comments?post=102581"}],"version-history":[{"count":17,"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/posts\/102581\/revisions"}],"predecessor-version":[{"id":127445,"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/posts\/102581\/revisions\/127445"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/media\/102650"}],"wp:attachment":[{"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/media?parent=102581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/categories?post=102581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.stellarinfo.com\/blog\/wp-json\/wp\/v2\/tags?post=102581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}