Angry Birds: Toy Ghouls’ new toys
AI Summary
Toy Ghouls, a financially motivated threat actor active since 2025, has developed two custom backdoor variants named mqtt-bird-agent and matrix-bird-agent, both version 0.1.0. These backdoors are deployed using Windows Remote Management (WinRM) and establish persistence via Windows services. The HiveMQ version communicates through the public broker.hivemq.com MQTT broker, while the Element version uses a malicious Element server at meet.element[.]tw for C2 communications, leveraging Matrix protocol rooms for command exchange. The backdoors collect system telemetry, execute commands via PowerShell or cmd, and use machine-bound encryption for configuration files, indicating increased sophistication in the group's tooling and operational security.
AI-extracted · verify before operational use
Indicators of Compromise 11 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | meet[.]element[.]tw | Details → |
| Domain | broker[.]hivemq[.]com | Details → |
| Filename | cplsupport.exe | Details → |
| Filename | wtass.exe | Details → |
| Filename | config.toml | Details → |
| MD5 | bfadbfee63a4f0bf19ec9deb8fa58f58 | Details → |
| MD5 | 7916c33688385525078bee504c90f359 | Details → |
| Registry User | HKLM\Software\synapse\Config\SealedConfig | Details → |
| Registry User | HKLM\Software\SynapseAgent\metrics_interval | Details → |
| Filename | cplsupport | Details → |
| Filename | wtas | Details → |