Date: 09/08/2026
Severity: High
Summary
Toy Ghouls group that has been targeting Russian organizations since 2025 and also using Lockbit and Babuk Ransomware. This group developed two custom backdoors, mqtt-bird-agent and matrix-bird-agent, using HiveMQ MQTT and Element/Matrix as command-and-control (C2) channels. The malware is delivered through WinRM, establishes Windows service persistence, performs system reconnaissance, and executes remote commands. The campaign demonstrates custom malware development, C2 evasion, remote command execution, and abuse of legitimate services to maintain control over compromised systems.
Indicators of Compromise (IOC) List
Domain/URLs | meet.element.tw |
Hash | BFADBEEE63A4F0BF19EC9DEB8FA58F58
7916C33688385525078BEE504C90F359
|
Registry Key | HKLM\Software\synapse\Config\SealedConfig HKLM\Software\SynapseAgent\metrics_interval |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "meet.element.tw" or url like "meet.element.tw" or siteurl like "meet.element.tw" |
Detection Query 2 : | md5hash IN ("BFADBEEE63A4F0BF19EC9DEB8FA58F58","7916C33688385525078BEE504C90F359")
|
Detection Query 3 : | datasourcename = "Windows Security" and eventtype = "4657" and objectname In ("HKLM\Software\synapse\Config\SealedConfig","HKLM\Software\SynapseAgent\metrics_interval") |
Detection Query 4 : | technologygroup = "EDR" and objectname In ("HKLM\Software\synapse\Config\SealedConfig","HKLM\Software\SynapseAgent\metrics_interval") |
Reference:
https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/