---
title: "ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API — Stuff That Spins"
description: "The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. \"In this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targe…"
	canonical: "https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api"
html: "https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api"
json: "https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api.json"
markdown: "https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api.md"
keywords: ["SpinGraph", "spin analysis", "GEO"]
date: "2026-07-02T13:04:13+00:00"
modified: "2026-07-05T04:42:15.321053+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api#article","headline":"ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API","description":"The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. \"In this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targe…","datePublished":"2026-07-02T13:04:13+00:00","dateModified":"2026-07-05T04:42:15.321053+00:00","url":"https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","author":{"@type":"Organization","name":"Stuff That Spins"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://thehackernews.com/2026/07/toddycat-linked-umbrij-malware-abuses.html","about":[],"mentions":[]},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API","item":"https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api"}]}]}
---

# ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

**Source:** Unknown  
**Published:** July 2, 2026  
**Original:** https://thehackernews.com/2026/07/toddycat-linked-umbrij-malware-abuses.html  

---
*HTML version: https://stuffthatspins.com/spin/toddycat-linked-umbrij-malware-abuses-oauth-to-access-gmail-via-google-api*
