Tuesday, 02 January 2024 12:17 GMT

Toy Ghouls Adopts Hivemq, Element For Windows Backdoors Arabian Post


(MENAFN- The Arabian Post) clearfix">Cybercrime group Toy Ghouls has deployed two custom Windows backdoors that use HiveMQ and the Matrix-based Element messaging system for command-and-control, marking a shift towards purpose-built malware.

Security researchers said the tools, identified as mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0, were first observed in early July. Toy Ghouls, also tracked as Bearlyfy, Laboo. boo and Feral Wolf, has targeted organisations in Russia and is assessed to be financially motivated.

The HiveMQ variant uses the public broker at broker. hivemq. com to exchange information and commands with infected machines. The Element version communicates through an attacker-controlled Element server operating on the Matrix protocol. Both approaches allow malicious traffic to blend with communications involving legitimate technologies, potentially complicating network-based detection.

MENAFN05092026000152002308ID1111624412



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story