Toy Ghouls Backdoor Uses HiveMQ and Element

Toy Ghouls debut custom Windows backdoors using HiveMQ and Element for C2

The Toy Ghouls backdoor is a newly observed custom tool that communicates through HiveMQ MQTT or the Element messaging platform. Kaspersky reported on 4 September 2026 that the financially motivated group deployed the malware after previously relying on public tools and ransomware.

Toy Ghouls backdoor marks a change in tactics

Toy Ghouls, also tracked as Bearlyfy, Laboo.boo and Feral Wolf, has targeted Russian organisations since 2025. Its earlier activity relied exclusively on tools obtained from public GitHub repositories, alongside leaked builders for the Babuk and LockBit ransomware families.

The group subsequently moved to its own GenieLocker ransomware. In early July 2026, researchers observed Toy Ghouls using a custom backdoor for the first time, representing a further development in its technical capabilities.

Researchers identified two versions of the Toy Ghouls backdoor. Both are version 0.1.0 and include the word “bird” in their internal names:

  • mqtt-bird-agent 0.1.0, which uses a HiveMQ MQTT broker for command and control.
  • matrix-bird-agent 0.1.0, which communicates through Element and its underlying Matrix infrastructure.

The use of legitimate communication services is significant because related network traffic may appear less unusual than connections to attacker-owned infrastructure. However, the research does not indicate that vulnerabilities in HiveMQ, Element or Matrix are being exploited. The attackers are abusing their normal communication functions as channels for malware control.

How the Toy Ghouls backdoor reaches Windows systems

Delivery through Windows Remote Management

In the observed campaign, the attackers delivered the backdoor executable and its configuration files through Windows Remote Management, commonly known as WinRM. WinRM is a legitimate Microsoft administration capability for remotely managing Windows computers.

The activity takes place on systems that have already been compromised. The report does not describe a new WinRM vulnerability or identify WinRM itself as the initial access route. Instead, Toy Ghouls uses the service as a practical way to transfer and execute its tools after obtaining access.

The group relies on open-source utilities including Evil-WinRM and WinRM-fs. Evil-WinRM provides a remote command shell, while WinRM-fs supports file operations over the same management channel. Their presence or execution in an environment should be assessed alongside authentication records, administrative activity and the appearance of the backdoor files.

Interactive execution and service installation

Both backdoor variants can run within an interactive command-line session. They can also establish persistence by installing themselves as Windows services, allowing the malware to restart with the operating system and operate without an attacker maintaining an interactive session.

The HiveMQ version accepts the –install option to install a system service and –uninstall to remove it. Its –service argument is used internally when Windows launches the installed service. Other options include specifying a configuration file, sealing sensitive configuration fields, displaying help and showing the malware version.

The Element version uses install and uninstall commands for service registration and removal. It also has an internal service command and supports a configuration path supplied with the -c or –config option. The help text describes the sample as a “Matrix monitoring agent”, language that could make the executable appear administrative at first glance.

Observed executable names in the published help output include cplsupport.exe for the HiveMQ edition and wtass.exe for the Element edition. File names alone are not definitive proof of compromise, but their combination with unusual WinRM activity, associated configuration paths and newly created services provides a stronger investigative lead.

Configuration paths and machine-bound encryption

The Toy Ghouls backdoor expects a TOML configuration file named config.toml. By default, it first searches the directory from which the executable was launched. If no file is found there, it checks a variant-specific location under the Windows ProgramData directory.

  • The Element version checks %PROGRAMDATA%\SynapseAgent\config.toml.
  • The HiveMQ version checks %PROGRAMDATA%\cplsupport\config.toml.
  • Either version can be directed to another location through its configuration option.

These paths offer concrete opportunities for threat hunting. Defenders can look for the directories, configuration files and corresponding executable activity, while recognising that a path match should be validated with service, process and network evidence.

The backdoor accepts both unencrypted configurations and files containing partially encrypted sections. When given an unencrypted configuration, it reads the file and then partially encrypts sensitive fields through a function named seal(). The HiveMQ variant also exposes this behaviour through its –seal option.

Encryption uses the ChaCha20-Poly1305 algorithm. The key is derived from the MachineGuid value stored under HKLM\Software\Microsoft\Cryptography in the Windows registry, binding the protected values to the infected computer.

This behaviour can complicate analysis if a configuration file is copied away from the original host without the relevant system information. It also gives incident responders a reason to preserve registry data and the complete configuration file during evidence collection, rather than examining only the executable.

Current exploitation and affected organisations

This is an observed malware campaign, not a theoretical vulnerability disclosure. Kaspersky first saw the custom Toy Ghouls backdoor in early July 2026 and published its technical findings on 4 September 2026.

The reporting associates Toy Ghouls with financially motivated operations against Russian organisations. It does not identify current UK victims or suggest that all users of HiveMQ, Element, Matrix or WinRM are affected. Exposure depends on an attacker first compromising a Windows environment and then deploying the backdoor.

No affected product version range is provided because the event concerns malicious software and abuse of legitimate services, rather than a flaw in a particular release. The only stated versions are mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0, which refer to the two malware builds.

What organisations should check

Organisations should focus on evidence directly connected to this campaign. Review WinRM sessions and remote file transfers that do not match approved administration, especially where Evil-WinRM or WinRM-fs may have been used.

  • Search for cplsupport.exe, wtass.exe and unexpected config.toml files.
  • Inspect the SynapseAgent and cplsupport directories under ProgramData.
  • Review newly installed Windows services and their executable arguments.
  • Correlate suspicious processes with MQTT, Element or Matrix communications.
  • Preserve the MachineGuid registry value when collecting forensic evidence.

These artefacts should be treated as investigation points rather than standalone confirmation. The strongest indication of Toy Ghouls backdoor activity will be a combination of unexplained WinRM access, matching files or paths, persistent service creation and unusual external communications.

Originally reported by securelist.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call