mqtt-bird-agent 0.1.0 is a custom Windows backdoor attributed to the financially motivated Toy Ghouls group, also known as Bearlyfy, Laboo.boo, and Feral Wolf. Observed targeting Russian organizations in 2026, it is deployed to previously compromised systems through Windows Remote Management using tools including Evil-WinRM and WinRM-fs. The backdoor can run interactively or establish persistence as a Windows service. It uses the public HiveMQ MQTT broker for command-and-control, reporting host status and periodic system telemetry, polling for commands, and returning command output. Collected telemetry includes host and system-performance information as well as public IP address and country data. Received commands are executed through a hidden PowerShell process. Sensitive configuration fields are protected with ChaCha20-Poly1305 using key material derived from a machine-specific Windows identifier, binding encrypted configuration data to the affected host.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We identified two versions of this backdoor: one uses the HiveMQ MQTT broker as its C2 server... mqtt-bird-agent 0.1.0 (HiveMQ version).
10 distinct techniques documented for this family, organized by ATT&CK tactic.
“The first version uses the public HiveMQ MQTT broker ... as its C2 server,” while “the attackers set up their own Element server running on the Matrix protocol ... as the C2 server.”
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Toy Ghouls Windows backdoor that persists as a Windows service, collects host status and system metrics, and obtains commands through an attacker-controlled HiveMQ MQTT cluster. It executes received commands through hidden PowerShell and machine-binds encrypted configuration data using ChaCha20-Poly1305 and the MachineGuid registry value.
A Windows backdoor used by Toy Ghouls that installs as a service, collects host and system telemetry, polls a HiveMQ broker for commands, executes received commands through hidden PowerShell, and returns command output to the C2.
A custom Windows backdoor used by Toy Ghouls that can run interactively or persist as a Windows service. It binds and encrypts portions of its configuration using a machine-derived key, reports host status and system metrics through the HiveMQ MQTT broker, retrieves commands, and executes them through hidden PowerShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.