Executive Summary

In July 2026, cybersecurity researchers identified two custom backdoors developed by the Toy Ghouls threat group (also known as Bearlyfy, Laboo.boo, and Feral Wolf), marking a significant evolution in their tactics. The financially motivated group, which has been targeting Russian organizations since 2025, deployed mqtt-bird-agent and matrix-bird-agent backdoors that use unconventional communication channels - the HiveMQ MQTT broker and Element messenger respectively. These backdoors are delivered via Windows Remote Management (WinRM) and establish persistence as Windows services, enabling full remote control of infected systems through encrypted configuration files and regular command execution capabilities. This represents a shift from the group's previous reliance on publicly available tools and leaked ransomware builders toward sophisticated custom malware development. The evolution of Toy Ghouls demonstrates the increasing sophistication of financially motivated threat actors who are developing novel communication methods to evade traditional security detection mechanisms and maintain persistent access to compromised environments.

Why This Matters Now

The emergence of backdoors using legitimate communication platforms like MQTT brokers and messaging services represents a growing trend where threat actors exploit trusted infrastructure to bypass security controls, making detection significantly more challenging for organizations.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The backdoors use legitimate communication platforms (HiveMQ MQTT broker and Element messenger) as command and control infrastructure, making their network traffic appear benign and harder to detect through traditional security monitoring.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained Toy Ghouls' lateral movement and command execution capabilities through workload segmentation and egress controls. The attack's blast radius would likely be reduced by limiting east-west traffic flows and restricting unauthorized outbound communications to MQTT and Element infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial WinRM exploitation would likely still succeed, but workload visibility and traffic inspection could help detect the malicious session establishment and tool deployment patterns.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Service installation would likely proceed, but segmentation policies could limit the scope of system access and constrain the backdoor's ability to communicate across network boundaries.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-system backdoor deployment would likely be significantly constrained by microsegmentation policies that restrict inter-workload communication and limit reachable attack surfaces.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: MQTT and Element communications would likely be detected and potentially blocked through traffic analysis, limiting the attackers' ability to maintain reliable command execution channels.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely be constrained by egress policies that restrict unauthorized outbound data flows and block connections to suspicious external infrastructure.

Impact (Mitigations)

Ransomware deployment scope would likely be significantly reduced to isolated network segments, limiting the overall organizational damage and recovery complexity compared to unrestricted lateral spread.

Impact at a Glance

Affected Business Functions

  • IT Infrastructure Management
  • Internal Communications
  • Data Security Operations
  • Remote System Administration
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $250,000

Data Exposure

System telemetry data including CPU usage, memory statistics, disk utilization, hostname information, and geographic location data. Potential for arbitrary command execution allowing access to sensitive files and internal network resources through PowerShell and command line interface access.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement via WinRM by enforcing least privilege access controls and microsegmentation policies
  • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to MQTT brokers and suspicious Element servers
  • Enable Multicloud Visibility & Control to detect anomalous WinRM usage patterns and suspicious service installations across hybrid environments
  • Strengthen East-West Traffic Security to monitor and control service-to-service communications that could facilitate backdoor deployment
  • Implement Threat Detection & Anomaly Response capabilities to identify covert communication channels and baseline deviations in system behavior

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image