Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Angry Birds: Toy Ghouls’ new toys

0
Medium
Published: 09/04/2026 (09/04/2026, 12:34:10 UTC)
Source: AlienVault OTX General

Description

Toy Ghouls, a financially motivated group targeting Russian organizations since 2025, has deployed custom backdoors for the first time. Two versions were identified: mqtt-bird-agent using HiveMQ MQTT broker and matrix-bird-agent using Element messenger as command and control infrastructure. The backdoors are delivered via Windows Remote Management (WinRM) using tools like Evil-WinRM and WinRM-fs. They establish persistence as Windows services, encrypt configuration files using ChaCha20-Poly1305 algorithm, and execute commands via PowerShell or command line. The backdoors collect system metrics including CPU load, memory, and disk usage, and communicate with attackers through unconventional channels. This represents a significant evolution from their previous reliance on public GitHub tools and leaked ransomware builders to custom-developed malware.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 10:38:21 UTC

Technical Analysis

The financially motivated threat actor Toy Ghouls has evolved its operational capabilities by deploying custom backdoors named mqtt-bird-agent and matrix-bird-agent. These backdoors leverage unconventional command and control channels via HiveMQ MQTT broker and Element messenger, respectively. Infection vectors include Windows Remote Management (WinRM) exploitation using tools like Evil-WinRM and WinRM-fs. The malware maintains persistence as Windows services and secures its configuration files using the ChaCha20-Poly1305 encryption algorithm. Execution of attacker commands occurs via PowerShell or command line interfaces. The backdoors also gather system performance metrics to inform attacker operations. This development represents a notable advancement from the group's prior reliance on public GitHub tools and leaked ransomware builders to a more sophisticated, custom malware infrastructure.

Potential Impact

The deployment of custom backdoors by Toy Ghouls enables persistent unauthorized access to targeted Windows systems, allowing attackers to execute arbitrary commands and maintain stealthy control. The use of encrypted configuration files and unconventional communication channels complicates detection and analysis. Collection of system metrics may facilitate tailored attacks or further compromise. Although no active exploits in the wild are reported, the presence of these backdoors poses a medium risk to affected organizations, particularly those targeted by this group.

Defensive Guidance

No official patches or fixes are available for this malware as it is custom-developed by the threat actor. Mitigation should focus on securing Windows Remote Management (WinRM) access by enforcing strong authentication, limiting access to trusted hosts, and monitoring for unusual WinRM activity. Network defenders should also monitor for indicators of compromise such as the provided hashes and domain 'meet.element.tw'. Employing endpoint detection and response solutions capable of identifying persistence as Windows services and unusual PowerShell or command line activity is recommended. Since this is a targeted threat, organizations should apply threat intelligence updates and harden systems accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/"]
Adversary
Toy Ghouls
Pulse Id
6a9abac288231f0634632e30
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashbfadbeee63a4f0bf19ec9deb8fa58f58
hash7916c33688385525078bee504c90f359

Domain

ValueDescriptionCopy
domainmeet.element.tw

Threat ID: 6a9e9063acd9273b4963a739

Added to database: 09/07/2026, 10:22:27 UTC

Last enriched: 09/07/2026, 10:38:21 UTC

Last updated: 09/07/2026, 12:54:31 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses