Angry Birds: Toy Ghouls’ new toys
Kaspersky documents Toy Ghouls deploying backdoors that abuse the HiveMQ MQTT broker and Matrix-based Element messenger as covert C2 channels — blending attack traffic into legitimate IoT and chat protocols.
Summary written by editorial AI · Source link below
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
Editorial Analysis
C2 traffic routed through legitimate IoT and messaging platforms evades traditional network defences, raising the bar for protocol-level detection in enterprise environments.
Review network egress policies to detect and alert on unexpected MQTT or Matrix protocol traffic from non-designated hosts.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Securelist (Kaspersky) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d