Toy Ghouls Use HiveMQ and Element for New Windows Backdoors

Toy Ghouls Use HiveMQ and Element for New Windows Backdoors

First seen 4 Sep 2026, 14:46 UTC SecurelistGbhackers 65.5

Article Content

Browse articles
ThreatCluster

The financially motivated group Toy Ghouls has introduced two new Windows backdoors named mqtt-bird-agent and matrix-bird-agent, utilizing HiveMQ and Element messenger for command-and-control communications. This marks a shift from their previous reliance on public tools and ransomware builders. The backdoors are delivered via Windows Remote Management (WinRM) using tools like Evil-WinRM and WinRM-fs. They can establish persistence as Windows services and accept both encrypted and unencrypted configuration files. The backdoors employ ChaCha20-Poly1305 encryption for configuration files, binding them to specific machines. The group has been active since 2025, primarily targeting Russian organizations. Current activity was first observed in July 2026, indicating an escalation in their tactics.

Key Points: • Toy Ghouls has developed two new Windows backdoors leveraging HiveMQ and Element. • The backdoors use Windows Remote Management for delivery and establish persistence as services. • Configuration files are encrypted using ChaCha20-Poly1305, binding them to specific machines.

Ask AI about this cluster

Timeline

2025-01-01
Toy Ghouls formed
The group began targeting Russian organizations, initially using public tools and leaked ransomware builders.
Securelist
2026-07-01
Custom backdoor deployment observed
Toy Ghouls began using their custom backdoors for the first time, marking a shift in their attack strategy.
Securelist
2026-09-04
New backdoors reported
Two new Windows backdoors named mqtt-bird-agent and matrix-bird-agent were detailed, utilizing HiveMQ and Element for C2.
Gbhackers