DEV Community

Mark0
Mark0

Posted on

Angry Birds: Toy Ghouls’ new toys

This report details the evolution of the Toy Ghouls threat group, a financially motivated actor that has transitioned from using public tools to developing custom malware, including the GenieLocker ransomware and two new backdoors. These backdoors, identified as mqtt-bird-agent and matrix-bird-agent, leverage unconventional command-and-control (C2) channels such as the HiveMQ MQTT broker and the Element messenger (Matrix protocol) to evade detection. The group primarily targets organizations using Windows Remote Management (WinRM) for initial delivery.

Technically, the backdoors feature sophisticated persistence mechanisms as Windows services and use machine-bound encryption for their configuration files via the ChaCha20-Poly1305 algorithm. By utilizing legitimate communication platforms like HiveMQ and Matrix, the attackers can mask their malicious traffic within standard network activity. The shift toward custom-built tools indicates an increasing level of sophistication in Toy Ghouls' operational capabilities, aimed at maintaining long-term control over infected systems.


Read Full Article

Top comments (0)