Toy Ghouls Deploy Custom Backdoors Using HiveMQ and Element for C2

· Original article ↗

Summary

Kaspersky details two custom Toy Ghouls backdoors targeting Russian organizations. Delivered via WinRM, they establish persistence on Windows and use HiveMQ or Element for command-and-control.

Key points

  • Toy Ghouls used custom backdoors in early July 2026, marking a shift from relying solely on public tools and leaked ransomware builders.
  • The group delivered the backdoors and configuration files to compromised Windows systems using WinRM and tools including Evil-WinRM and WinRM-fs.
  • The backdoors can run interactively or install as Windows services; their configuration data is partially encrypted using a machine-bound key.
  • The HiveMQ version communicates through the public HiveMQ MQTT broker, while the other uses an attacker-controlled Element server and Matrix room.
  • Both versions send device status and metrics, retrieve commands, and return command results; the HiveMQ version executes commands through PowerShell, while the Element version uses the Windows command line.
  • Kaspersky lists file hashes, registry keys, service names, and domains as indicators of compromise.

Article Details

Attack Vectors
  • Toy Ghouls used Windows Remote Management (WinRM), including Evil-WinRM and WinRM-fs, to deliver the backdoors and configuration files to compromised systems.
  • The backdoors can persist as Windows services.
  • The backdoors receive commands through a HiveMQ MQTT broker or an attacker-operated Element server and execute them using PowerShell or the Windows command line.
Defensive Notes
  • Review WinRM activity and investigate unexpected use of Evil-WinRM or WinRM-fs to deliver files.
  • Check for unexpected services named cplsupport or wtas and the reported registry keys HKLM\Software\synapse\Config\SealedConfig and HKLM\Software\SynapseAgent\metrics_interval.
  • Investigate outbound connections to meet.element[.]tw and unusual use of broker.hivemq.com for command-and-control traffic.
  • Use the reported malware hashes and Kaspersky verdicts to support detection.

Indicators of compromise

TypeIndicatorContext
DOMAINmeet[.]element[.]twAttacker-operated Element server used for command-and-control.
MD57916c33688385525078bee504c90f359MD5 hash of the reported backdoor file wtass.exe.
MD5bfadbeee63a4f0bf19ec9deb8fa58f58MD5 hash of the reported backdoor file cplsupport.exe.

MITRE ATT&CK

Threat Actors

Malware

Products

Tools

Countries

Related Articles