HomeCyber BalkansHackers Utilize HiveMQ and Element Messenger as Control Channels for Windows Backdoors

Hackers Utilize HiveMQ and Element Messenger as Control Channels for Windows Backdoors

Published on

spot_img

Toy Ghouls Expands Malware Arsenal with Advanced Backdoors

In a significant development within the cybersecurity landscape, the financially driven threat actor group known as Toy Ghouls has broadened its portfolio of custom malware. This expansion includes the introduction of two advanced Windows backdoors that exploit HiveMQ’s public MQTT infrastructure alongside the Element messaging ecosystem, which is based on Matrix, for command-and-control (C2) communications. This evolution underscores a strategic shift in their operational tactics, moving away from the prior reliance on widely accessible tools and leaked ransomware builders.

Previously, Toy Ghouls had used such publicly available resources before establishing its proprietary GenieLocker ransomware family. The change in methodologies marks a concerning escalation in the sophistication of their cybercriminal efforts. This group, which is also identified by aliases such as Bearlyfy, Laboo.boo, and Feral Wolf, has primarily focused its attacks on organizations within Russia since as early as 2025.

The emergence of the new custom backdoors was first recorded by cybersecurity researchers in early July 2026. Two initial versions emerged during this observation: the mqtt-bird-agent 0.1.0 and the matrix-bird-agent 0.1.0. The former utilizes the HiveMQ MQTT broker for remote communication, while the latter connects through an attacker-controlled Element/Matrix server.

Such an approach indicates that the operators are likely exploiting legitimate administrative access for deploying these payloads, rather than conducting broad, indiscriminate phishing campaigns. This refinement in targeting suggests a higher level of planning and methodology involved in their operations.

Both backdoor variants possess the capability to run interactively or register themselves as persistent Windows services. The version associated with HiveMQ operates under the process name cplsupport.exe, featuring various command-line options including --install, --uninstall, and --seal. Similarly, the Element variant is executed under wtass.exe and encompasses commands such as install, uninstall, and an internal service command for the installed Windows service.

The HiveMQ backdoor inspects its execution directory for a configuration file named config.toml, and if absent, subsequently searches the directory at %PROGRAMDATA%\cplsupport\config.toml. The Matrix variant follows a similar protocol, seeking its configuration file at %PROGRAMDATA%\SynapseAgent\config.toml. This design offers the operators substantial flexibility to deploy their malwares in temporary locations before they relocate them to more permanent paths within the system.

A distinctive characteristic of these backdoors is their method for configuration encryption, which is bound to the compromised machine. The HiveMQ backdoor employs the ChaCha20-Poly1305 encryption algorithm for safeguarding sensitive configuration data, using a key derived from the Windows registry value located at HKLM\Software\Microsoft\Cryptography\MachineGuid. This mechanism ensures that the encrypted configuration values cannot be transferred successfully to any other machine, as the inability to recover configuration would result in immediate termination of the malware’s operation.

In contrast, the Element variant enhances persistence by deleting its original configuration file post-initial execution. Instead, it retains the relevant encrypted information within the registry at HKLM\Software\synapse\Config\SealedConfig. This data encompasses crucial details, including the attackers’ Element server and associated access credentials.

Both backdoor variants exhibit a method for gathering essential information about the victim’s host. Upon startup, each backdoor contacts ip-api.com/json to retrieve the public IP address and geographical location of the compromised system. The HiveMQ version subsequently connects to broker.hivemq.com over port 8883, which is under the attackers’ control, to relay system telemetry, status updates, and execute commands.

The HiveMQ backdoor is programmed to transmit numerous metrics encompassing hostname, online status, CPU consumption, memory usage, disk utilization, system load, and overall uptime. It utilizes hidden PowerShell instructions for executing commands and subsequently reports standard outputs, error outputs, execution times, and exit codes back to the operators. Meanwhile, the Element-based version communicates with matrices over a proprietary server and sends custom events such as m.bird.status, m.bird.metrics, and m.bird.cmd_response.

Operators can manipulate telemetry intervals, ranging from five seconds to an expansive 3,600 seconds, through messages that adjust configurations saved under the registry path HKLM\Software\SynapseAgent\metrics_interval. Commands prefixed with cmd: are executed through the Windows command shell, with the panel-bot account identified as the conduit for command dispatch.

The backdoors are equipped with robust capabilities for durable remote access, host monitoring, and arbitrary command execution, supporting a wide range of malicious activities, including reconnaissance, lateral movement, payload staging, and ransomware deployment. Their discovery comes in the wake of Toy Ghouls’ transition towards in-house developed ransomware like GenieLocker, which is capable of targeting Windows, Linux, and VMware ESXi environments.

Cybersecurity professionals are urged to remain vigilant for any suspicious WinRM activity, service registrations, or any modifications involving the identified ProgramData directories. A focus on behavioral detection, rather than simply blocking known domains, is imperative, as the use of familiar cloud infrastructures makes distinguishing malicious C2 traffic from legitimate operations increasingly challenging.

As a precautionary measure, Windows security solutions have begun identifying these threats with various heuristics, highlighting the growing need for heightened awareness and rapid response to these sophisticated attacks.

Source link

Latest articles

Bidding War for Defunct Spirit Airlines Employee Data Continues

Spirit Airlines' Data Acquisition in Uncertain Times: A $12.5 Million Offer on the Table The...

G7 Calls for Quick Implementation of Quantum-Safe Cybersecurity Regulations

G7 Urges Acceleration of Transition to Quantum-Safe Encryption In a pivotal move, the Group of...

KnowBe4 to Test AI Trust at Leeds Digital Festival

KnowBe4 to Address AI Trust Issues at Leeds Digital Festival 2026 In a rapidly evolving...

More like this

Bidding War for Defunct Spirit Airlines Employee Data Continues

Spirit Airlines' Data Acquisition in Uncertain Times: A $12.5 Million Offer on the Table The...

G7 Calls for Quick Implementation of Quantum-Safe Cybersecurity Regulations

G7 Urges Acceleration of Transition to Quantum-Safe Encryption In a pivotal move, the Group of...