Angry Birds: Toy Ghouls’ new toys

    Date: 09/08/2026

    Severity: High

    Summary

    Toy Ghouls group that has been targeting Russian organizations since 2025 and also using Lockbit and Babuk Ransomware. This group developed two custom backdoors, mqtt-bird-agent and matrix-bird-agent, using HiveMQ MQTT and Element/Matrix as command-and-control (C2) channels. The malware is delivered through WinRM, establishes Windows service persistence, performs system reconnaissance, and executes remote commands. The campaign demonstrates custom malware development, C2 evasion, remote command execution, and abuse of legitimate services to maintain control over compromised systems.

    Indicators of Compromise (IOC) List 

    Domain/URLs

    meet.element.tw

    Hash

    BFADBEEE63A4F0BF19EC9DEB8FA58F58

    7916C33688385525078BEE504C90F359

    Registry Key

    HKLM\Software\synapse\Config\SealedConfig

    HKLM\Software\SynapseAgent\metrics_interval

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "meet.element.tw" or url like "meet.element.tw" or siteurl like "meet.element.tw"

    Detection Query 2 :

    md5hash IN ("BFADBEEE63A4F0BF19EC9DEB8FA58F58","7916C33688385525078BEE504C90F359")

    Detection Query 3 :

    datasourcename = "Windows Security" and eventtype = "4657" and objectname In ("HKLM\Software\synapse\Config\SealedConfig","HKLM\Software\SynapseAgent\metrics_interval")

    Detection Query 4 :

    technologygroup = "EDR" and objectname In ("HKLM\Software\synapse\Config\SealedConfig","HKLM\Software\SynapseAgent\metrics_interval")

    Reference: 

    https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ 


    Tags

    MalwareThreat ActorBackdoorRussiaRansomwareLockbitWinRMRCE

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags