Securelist
Toy Ghouls Use HiveMQ and Element for New Windows Backdoors
Article Content
The financially motivated group Toy Ghouls has introduced two new Windows backdoors named mqtt-bird-agent and matrix-bird-agent, utilizing HiveMQ and Element messenger for command-and-control communications. This marks a shift from their previous reliance on public tools and ransomware builders. The backdoors are delivered via Windows Remote Management (WinRM) using tools like Evil-WinRM and WinRM-fs. They can establish persistence as Windows services and accept both encrypted and unencrypted configuration files. The backdoors employ ChaCha20-Poly1305 encryption for configuration files, binding them to specific machines. The group has been active since 2025, primarily targeting Russian organizations. Current activity was first observed in July 2026, indicating an escalation in their tactics.
Key Points: • Toy Ghouls has developed two new Windows backdoors leveraging HiveMQ and Element. • The backdoors use Windows Remote Management for delivery and establish persistence as services. • Configuration files are encrypted using ChaCha20-Poly1305, binding them to specific machines.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.