Toy Ghouls Deploy Custom Backdoors Using HiveMQ and Element for C2

Summary
Kaspersky details two custom Toy Ghouls backdoors targeting Russian organizations. Delivered via WinRM, they establish persistence on Windows and use HiveMQ or Element for command-and-control.
Key points
- Toy Ghouls used custom backdoors in early July 2026, marking a shift from relying solely on public tools and leaked ransomware builders.
- The group delivered the backdoors and configuration files to compromised Windows systems using WinRM and tools including Evil-WinRM and WinRM-fs.
- The backdoors can run interactively or install as Windows services; their configuration data is partially encrypted using a machine-bound key.
- The HiveMQ version communicates through the public HiveMQ MQTT broker, while the other uses an attacker-controlled Element server and Matrix room.
- Both versions send device status and metrics, retrieve commands, and return command results; the HiveMQ version executes commands through PowerShell, while the Element version uses the Windows command line.
- Kaspersky lists file hashes, registry keys, service names, and domains as indicators of compromise.
Article Details
- Attack Vectors
- Toy Ghouls used Windows Remote Management (WinRM), including Evil-WinRM and WinRM-fs, to deliver the backdoors and configuration files to compromised systems.
- The backdoors can persist as Windows services.
- The backdoors receive commands through a HiveMQ MQTT broker or an attacker-operated Element server and execute them using PowerShell or the Windows command line.
- Defensive Notes
- Review WinRM activity and investigate unexpected use of Evil-WinRM or WinRM-fs to deliver files.
- Check for unexpected services named cplsupport or wtas and the reported registry keys HKLM\Software\synapse\Config\SealedConfig and HKLM\Software\SynapseAgent\metrics_interval.
- Investigate outbound connections to meet.element[.]tw and unusual use of broker.hivemq.com for command-and-control traffic.
- Use the reported malware hashes and Kaspersky verdicts to support detection.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | meet[.]element[.]tw | Attacker-operated Element server used for command-and-control. |
| MD5 | 7916c33688385525078bee504c90f359 | MD5 hash of the reported backdoor file wtass.exe. |
| MD5 | bfadbeee63a4f0bf19ec9deb8fa58f58 | MD5 hash of the reported backdoor file cplsupport.exe. |
MITRE ATT&CK
T1021.006 · Windows Remote ManagementThe attackers used WinRM to deliver backdoors and configuration files to compromised systems.T1059.001 · PowerShellThe HiveMQ version executes received commands through PowerShell.exe with -NonInteractive, -NoProfile, and -Command parameters.T1059.003 · Windows Command ShellThe Element version executes received commands through the Windows command-line interface.T1112 · Modify RegistryThe Element version writes its sealed configuration and metrics interval to Windows registry keys.T1543.003 · Windows ServiceThe backdoor can establish persistence by installing itself as a Windows service.
Threat Actors
BearlyfyAlternate name for Toy Ghouls, according to the article.Feral WolfAlternate name for Toy Ghouls, according to the article.Laboo.booAlternate name for Toy Ghouls, according to the article.Toy GhoulsFinancially motivated group reported targeting Russian organizations since 2025; the article identifies Bearlyfy, Laboo.boo, and Feral Wolf as alternate names.
Malware
GenieLockerThe attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker.matrix-bird-agentmatrix-bird-agent 0.1.0 (Element version)mqtt-bird-agentmqtt-bird-agent 0.1.0 (HiveMQ version)
Products
ElementWe identified two versions of this backdoor: one uses the HiveMQ MQTT broker as its C2 server, while the other relies on the Element messenger.HiveMQWe identified two versions of this backdoor: one uses the HiveMQ MQTT broker as its C2 server, while the other relies on the Element messenger.Microsoft WindowsIn this campaign, the attackers use Windows Remote Management (WinRM) to deliver the backdoors and their configuration files to compromised systems.
Tools
Evil-WinRMThe group relies on open-source tools such as Evil-WinRM and WinRM-fs to do this.PowerShellCommands are executed via PowerShell.exe in hidden mode, using the -NonInteractive -NoProfile -Command parameters.WinRM-fsThe group relies on open-source tools such as Evil-WinRM and WinRM-fs to do this.