Threat Advisory

Toy Ghouls Group Utilize MQTT and Matrix Channels Using Disguised Windows Processes

Threat: Malware
Threat Actor Name: Toy Ghouls
Threat Actor Type: Financially Motivated
Targeted Region: Global
Alias: Bearlyfy, Laboo.boo, Feral Wolf
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A financially motivated threat group known as Toy Ghouls has expanded its toolkit with two custom Windows backdoors designed to provide persistent remote access to compromised systems. The backdoors, identified as mqtt-bird-agent and matrix-bird-agent, use unconventional command-and-control (C2) channels: the first communicates through the HiveMQ MQTT broker, while the second leverages the Matrix-based Element messaging platform. The activity represents a shift toward purpose-built malware capable of maintaining access and remotely controlling infected systems.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A financially motivated threat group known as Toy Ghouls has expanded its toolkit with two custom Windows backdoors designed to provide persistent remote access to compromised systems. The backdoors, identified as mqtt-bird-agent and matrix-bird-agent, use unconventional command-and-control (C2) channels: the first communicates through the HiveMQ MQTT broker, while the second leverages the Matrix-based Element messaging platform. The activity represents a shift toward purpose-built malware capable of maintaining access and remotely controlling infected systems.[emaillocker id="1283"]

The backdoors are delivered to compromised Windows systems through Windows Remote Management (WinRM) and can be deployed using tools such as Evil-WinRM and WinRM-fs. Both variants can execute interactively or establish persistence as Windows services. Their configuration files contain sensitive C2 information and are protected using ChaCha20-Poly1305, with encryption keys derived from the system's MachineGuid. The HiveMQ variant communicates through a public MQTT broker, sending system status and resource information while periodically retrieving commands and executing them through hidden PowerShell sessions. The Element variant connects to an attacker-controlled Matrix server and uses dedicated rooms to exchange system information and commands, with received commands executed through the Windows command-line interface. Both variants also collect public IP and geographic information and can return command results to the C2 infrastructure.

The emergence of these backdoors demonstrates an evolution in Toy Ghouls' attack capabilities from reliance on publicly available tools toward purpose-built malware. By abusing legitimate communication infrastructure such as MQTT and Matrix, the malware can blend command-and-control traffic with legitimate network activity while maintaining persistent remote access. Organizations should monitor WinRM activity, unexpected Windows service creation, suspicious PowerShell execution, unusual connections to MQTT or Matrix infrastructure, and unauthorized configuration or registry modifications to identify potential infections and limit further compromise.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1543.003 Create or Modify System Process Windows Service
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1105 Ingress Tool Transfer -

 

MBC PROFILE:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Persistence F0012 Registry Run Keys / Startup Folder
Execution B0023 Install Additional Program
Impact B0022 Remote Access
Exfiltration E1020 Automated Exfiltration
Anti-Static Analysis E1027 Obfuscated Files or Information
Execution E1204 User Execution

 

REFERENCES:

The following reports contain further technical details:
https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/

[/emaillocker]
crossmenu