Executive Summary
In July 2026, cybersecurity researchers identified two custom backdoors developed by the Toy Ghouls threat group (also known as Bearlyfy, Laboo.boo, and Feral Wolf), marking a significant evolution in their tactics. The financially motivated group, which has been targeting Russian organizations since 2025, deployed mqtt-bird-agent and matrix-bird-agent backdoors that use unconventional communication channels - the HiveMQ MQTT broker and Element messenger respectively. These backdoors are delivered via Windows Remote Management (WinRM) and establish persistence as Windows services, enabling full remote control of infected systems through encrypted configuration files and regular command execution capabilities. This represents a shift from the group's previous reliance on publicly available tools and leaked ransomware builders toward sophisticated custom malware development. The evolution of Toy Ghouls demonstrates the increasing sophistication of financially motivated threat actors who are developing novel communication methods to evade traditional security detection mechanisms and maintain persistent access to compromised environments.
Why This Matters Now
The emergence of backdoors using legitimate communication platforms like MQTT brokers and messaging services represents a growing trend where threat actors exploit trusted infrastructure to bypass security controls, making detection significantly more challenging for organizations.
Attack Path Analysis
Toy Ghouls compromised systems using WinRM exploitation to deploy custom backdoors. The malware established persistence as Windows services and communicated via HiveMQ MQTT broker and Element messenger for command execution. The group evolved from using public tools to custom backdoors, enabling prolonged control and evasion of traditional detection methods.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers used Windows Remote Management (WinRM) exploitation with tools like Evil-WinRM and WinRM-fs to gain initial access to target systems
MITRE ATT&CK® Techniques
Remote Services: Windows Remote Management
Create or Modify System Process: Windows Service
Deobfuscate/Decode Files or Information
Command and Scripting Interpreter: PowerShell
Application Layer Protocol: Web Protocols
Encrypted Channel: Symmetric Cryptography
System Information Discovery
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Device Monitoring and Threat Detection
Control ID: Device Security - Advanced
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
Digital Operational Resilience Act (DORA) – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – Intrusion Detection and Prevention Systems
Control ID: 11.5.1
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.8.16
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Toy Ghouls backdoor targeting Russian organizations poses severe risks through encrypted traffic exploitation, lateral movement capabilities, and exfiltration bypassing traditional perimeter defenses.
Government Administration
Custom backdoors using HiveMQ and Element protocols enable persistent command control, threatening sensitive government systems through WinRM delivery and registry-based persistence mechanisms.
Information Technology/IT
Zero trust segmentation vulnerabilities and east-west traffic monitoring gaps allow threat actors to establish persistent access using unconventional communication channels like MQTT brokers.
Telecommunications
Multi-cloud visibility limitations and egress security weaknesses create exposure to sophisticated backdoors communicating through legitimate messaging platforms and encrypted private circuits.
Sources
- Angry Birds: Toy Ghouls’ new toyshttps://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/Verified
- HiveMQ MQTT Broker - Official Documentationhttps://www.hivemq.com/mqtt-broker/Verified
- Element Matrix Protocol Securityhttps://element.io/securityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained Toy Ghouls' lateral movement and command execution capabilities through workload segmentation and egress controls. The attack's blast radius would likely be reduced by limiting east-west traffic flows and restricting unauthorized outbound communications to MQTT and Element infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial WinRM exploitation would likely still succeed, but workload visibility and traffic inspection could help detect the malicious session establishment and tool deployment patterns.
Control: Zero Trust Segmentation
Mitigation: Service installation would likely proceed, but segmentation policies could limit the scope of system access and constrain the backdoor's ability to communicate across network boundaries.
Control: East-West Traffic Security
Mitigation: Cross-system backdoor deployment would likely be significantly constrained by microsegmentation policies that restrict inter-workload communication and limit reachable attack surfaces.
Control: Multicloud Visibility & Control
Mitigation: MQTT and Element communications would likely be detected and potentially blocked through traffic analysis, limiting the attackers' ability to maintain reliable command execution channels.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained by egress policies that restrict unauthorized outbound data flows and block connections to suspicious external infrastructure.
Ransomware deployment scope would likely be significantly reduced to isolated network segments, limiting the overall organizational damage and recovery complexity compared to unrestricted lateral spread.
Impact at a Glance
Affected Business Functions
- IT Infrastructure Management
- Internal Communications
- Data Security Operations
- Remote System Administration
Estimated downtime: 7 days
Estimated loss: $250,000
System telemetry data including CPU usage, memory statistics, disk utilization, hostname information, and geographic location data. Potential for arbitrary command execution allowing access to sensitive files and internal network resources through PowerShell and command line interface access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement via WinRM by enforcing least privilege access controls and microsegmentation policies
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to MQTT brokers and suspicious Element servers
- • Enable Multicloud Visibility & Control to detect anomalous WinRM usage patterns and suspicious service installations across hybrid environments
- • Strengthen East-West Traffic Security to monitor and control service-to-service communications that could facilitate backdoor deployment
- • Implement Threat Detection & Anomaly Response capabilities to identify covert communication channels and baseline deviations in system behavior



