This article examines the evolution of the Toy Ghouls threat group (also known as Bearlyfy), which has shifted from using public GitHub tools and leaked ransomware builders to developing sophisticated custom backdoors. Recently identified as 'mqtt-bird-agent' and 'matrix-bird-agent,' these tools are used to target organizations with advanced persistence mechanisms and unconventional command-and-control (C2) communication channels, specifically utilizing the HiveMQ MQTT broker and the Matrix-based Element messenger.
Technically, the group leverages Windows Remote Management (WinRM) for delivery and installs the backdoors as system services. A notable feature is the use of machine-bound encryption for configuration files, which prevents the malware from running if moved to a different environment. This transition toward custom-built infrastructure and stealthy communication protocols indicates that Toy Ghouls is refining its methods to evade traditional detection and maintain long-term access to compromised systems.
Top comments (0)