Toy Ghouls Deploy New Windows Backdoors Leveraging HiveMQ and Element for C2
A financially motivated cybercrime group known as Toy Ghouls has introduced two Windows backdoors that hide their command-and-control traffic inside legitimate cloud services, specifically HiveMQ's public MQTT broker network and the Matrix‑based Element messaging platform.
HiveMQ provides a publicly accessible MQTT infrastructure that many Internet of Things devices and applications use for lightweight messaging. By embedding its traffic in MQTT topics that appear normal to network monitors, the new backdoor can receive instructions and exfiltrate data while blending into the high volume of legitimate broker traffic.
Element, an open‑source client for the Matrix communication protocol, offers end‑to‑end encrypted chat rooms and direct messages. Toy Ghouls has repurposed this ecosystem, routing control commands through seemingly ordinary chat messages. Because Matrix traffic is encrypted and often allowed through corporate firewalls, the backdoor gains a stealthy conduit that evades many traditional detection tools.
The group’s shift toward abusing public communication services follows a broader trend among financially driven actors seeking to reduce the operational overhead of maintaining dedicated servers. Prior campaigns attributed to Toy Ghouls have focused on credential theft and ransomware deployment; the addition of these two backdoors expands their toolkit and provides more resilient access once a victim machine is compromised.
Security researchers warn that the use of legitimate platforms for malicious C2 complicates incident response. Detecting anomalous MQTT or Matrix activity requires baseline profiling of normal traffic patterns and may involve deep packet inspection or behavioral analytics. Organizations are advised to monitor outbound connections to public MQTT brokers, enforce strict application allowlists, and apply zero‑trust principles to messaging applications.
As Toy Ghouls continues to refine its methods, defenders can expect further exploitation of widely trusted services. Ongoing collaboration between threat intel communities and service providers will be essential to identify abuse patterns and develop mitigations without disrupting legitimate users.
Comments (0)
Be the first to comment.
Join the discussion