$ techbeacon▋
Ransomware

Toy Ghouls Deploy New Windows Backdoors Leveraging HiveMQ and Element for C2

Toy Ghouls Deploy New Windows Backdoors Leveraging HiveMQ and Element for C2

A financially motivated cybercrime group known as Toy Ghouls has introduced two Windows backdoors that hide their command-and-control traffic inside legitimate cloud services, specifically HiveMQ's public MQTT broker network and the Matrix‑based Element messaging platform.

HiveMQ provides a publicly accessible MQTT infrastructure that many Internet of Things devices and applications use for lightweight messaging. By embedding its traffic in MQTT topics that appear normal to network monitors, the new backdoor can receive instructions and exfiltrate data while blending into the high volume of legitimate broker traffic.

Element, an open‑source client for the Matrix communication protocol, offers end‑to‑end encrypted chat rooms and direct messages. Toy Ghouls has repurposed this ecosystem, routing control commands through seemingly ordinary chat messages. Because Matrix traffic is encrypted and often allowed through corporate firewalls, the backdoor gains a stealthy conduit that evades many traditional detection tools.

The group’s shift toward abusing public communication services follows a broader trend among financially driven actors seeking to reduce the operational overhead of maintaining dedicated servers. Prior campaigns attributed to Toy Ghouls have focused on credential theft and ransomware deployment; the addition of these two backdoors expands their toolkit and provides more resilient access once a victim machine is compromised.

Security researchers warn that the use of legitimate platforms for malicious C2 complicates incident response. Detecting anomalous MQTT or Matrix activity requires baseline profiling of normal traffic patterns and may involve deep packet inspection or behavioral analytics. Organizations are advised to monitor outbound connections to public MQTT brokers, enforce strict application allowlists, and apply zero‑trust principles to messaging applications.

As Toy Ghouls continues to refine its methods, defenders can expect further exploitation of widely trusted services. Ongoing collaboration between threat intel communities and service providers will be essential to identify abuse patterns and develop mitigations without disrupting legitimate users.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related