Toy Ghouls Adopts Hivemq, Element For Windows Backdoors Arabian Post
Security researchers said the tools, identified as mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0, were first observed in early July. Toy Ghouls, also tracked as Bearlyfy, Laboo. boo and Feral Wolf, has targeted organisations in Russia and is assessed to be financially motivated.
The HiveMQ variant uses the public broker at broker. hivemq. com to exchange information and commands with infected machines. The Element version communicates through an attacker-controlled Element server operating on the Matrix protocol. Both approaches allow malicious traffic to blend with communications involving legitimate technologies, potentially complicating network-based detection.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment