securelist · Crawled Sep 4, 2026

Angry Birds: Toy Ghouls’ new toys

11 IoCs
Read original article ↗

AI Summary

Toy Ghouls, a financially motivated threat actor active since 2025, has developed two custom backdoor variants named mqtt-bird-agent and matrix-bird-agent, both version 0.1.0. These backdoors are deployed using Windows Remote Management (WinRM) and establish persistence via Windows services. The HiveMQ version communicates through the public broker.hivemq.com MQTT broker, while the Element version uses a malicious Element server at meet.element[.]tw for C2 communications, leveraging Matrix protocol rooms for command exchange. The backdoors collect system telemetry, execute commands via PowerShell or cmd, and use machine-bound encryption for configuration files, indicating increased sophistication in the group's tooling and operational security.

AI-extracted · verify before operational use

Indicators of Compromise 11 extracted

Type Value Detail
Domain meet[.]element[.]tw Details →
Domain broker[.]hivemq[.]com Details →
Filename cplsupport.exe Details →
Filename wtass.exe Details →
Filename config.toml Details →
MD5 bfadbfee63a4f0bf19ec9deb8fa58f58 Details →
MD5 7916c33688385525078bee504c90f359 Details →
Registry User HKLM\Software\synapse\Config\SealedConfig Details →
Registry User HKLM\Software\SynapseAgent\metrics_interval Details →
Filename cplsupport Details →
Filename wtas Details →