Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The new backdoors are called mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0. The HiveMQ version uses the public broker.hivemq.com MQTT service as its command-and-control channel.
The new backdoors are called mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0. The HiveMQ version uses the public broker.hivemq.com MQTT service as its command-and-control channel.
The new backdoors are called mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0. The HiveMQ version uses the public broker.hivemq.com MQTT service as its command-and-control channel.
The new backdoors are called mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0. The HiveMQ version uses the public broker.hivemq.com MQTT service as its command-and-control channel.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
В начале работы обе версии бэкдора отправляют GET-запрос на URL http://ip-api.com/json, чтобы определить публичный IP-адрес системы и его принадлежность к стране.
Domain ip-api.com Legitimate service queried to identify the victim system’s public IP address and country.
Toy Ghouls uses Windows Remote Management, or WinRM, to place the backdoors and their configuration files on already compromised systems. The attackers use Evil-WinRM and WinRM-fs, tools that can help move files and run remote commands across Windows environments.
“The first version uses the public HiveMQ MQTT broker ... as its C2 server” and “the attackers set up their own Element server running on the Matrix protocol ... as the C2 server.”
The HiveMQ version uses the public broker.hivemq.com MQTT service as its command-and-control channel. It reports whether a device is online, sends information such as processor usage and free memory, and retrieves instructions.
Атакующие создали свой кластер и использовали его для получения телеметрии со скомпрометированной системы, а также для отправки команд бэкдору.
The HiveMQ version uses the public broker.hivemq.com MQTT service as its command-and-control channel... The second version uses an attacker-controlled Element server based on the Matrix protocol. It sends device status messages to a designated room, receives commands from an account called panel-bot.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom Windows backdoor used by Toy Ghouls. It communicates over MQTT through the public HiveMQ broker, reports host availability and system metrics including processor usage and free memory, retrieves commands, and executes them through a hidden PowerShell process. It can run interactively or persist as a Windows service named cplsupport.
Custom Windows backdoor used by Toy Ghouls. It communicates through the public HiveMQ MQTT broker, reports host status and system metrics, retrieves commands, and executes them through a hidden PowerShell process. It can run interactively or persist as a Windows service named cplsupport.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.