Toy Ghouls is a financially motivated ransomware and extortion group active against Russian organizations since at least January 2025. It is also tracked as Bearlyfy, Laboo.boo, Feral Wolf, and Labubu. The group initially used publicly available tools and leaked ransomware builders, deploying RedAlert, LockBit, and Babuk, before developing the cross-platform GenieLocker ransomware for Windows, Linux, and VMware ESXi environments. Toy Ghouls has targeted manufacturing most prominently, as well as construction, financial services, retail, and technology organizations. Observed initial-access methods include compromised partner infrastructure, exposed services, valid credentials associated with remote-access services, and insecure enterprise application-server configurations. Post-compromise activity includes network and host reconnaissance, credential dumping and password-store access, remote execution, RDP- and SSH-based lateral movement, reverse SSH tunneling, and broad ransomware deployment using remote administration utilities. It has also abused Active Directory Certificate Services misconfigurations and credential-based domain-compromise techniques. The group employs persistence through Windows services, scheduled tasks, and locally created accounts, while defense evasion includes clearing event logs, deleting remote-access artifacts, modifying firewall settings, and removing staging materials. In 2026, Toy Ghouls introduced custom Windows backdoors, mqtt-bird-agent and matrix-bird-agent, which use MQTT and Matrix/Element-based command-and-control channels, collect host telemetry, execute operator commands, and can persist as services. GenieLocker includes Windows and Linux/ESXi variants; the latter can disrupt virtualized environments by stopping virtual machines and encrypting virtual disks. Available reporting indicates an encryption-focused extortion model, with no observed data theft, public leak site, or double-extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
70 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targets Russian organizations using LockBit and Babuk ransomware and custom mqtt-bird-agent and matrix-bird-agent backdoors. The group uses HiveMQ MQTT and Element/Matrix for C2, delivers malware through WinRM, establishes Windows-service persistence, conducts system reconnaissance, and executes remote commands.
Uses newly discovered backdoors for command-and-control, including variants communicating through a HiveMQ MQTT broker and the Matrix-based Element messenger.
Financially motivated group targeting Russian organizations. It evolved from reliance on public tools and leaked ransomware builders to deploying custom Windows backdoors that use MQTT and Matrix/Element services for command-and-control and persistence.
Financially motivated group targeting Russian organizations since 2025. It deploys mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0 on already compromised Windows systems to maintain persistent remote control, collect host telemetry, and execute commands over HiveMQ MQTT or an attacker-controlled Matrix/Element server.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.