securityonline.info 9/4/2026, 11:35:51 AM · external

Toy Ghouls Backdoor Uses HiveMQ and Element for C2

Toy Ghouls Backdoor Uses HiveMQ and Element for C2

TOY Ghouls, a financially motivated hacker group active since 2025, has developed a custom backdoor for Windows systems, attributed by Kaspersky. This backdoor operates in two versions using HiveMQ and Element for command-and-control (C2). The malware is delivered via Windows Remote Management and installs itself as a persistent service. Encrypting its configuration using ChaCha20-Poly1305, it ensures settings are machine-specific.

The HiveMQ version communicates through MQTT, while the Element version uses a direct command-line interface. Kaspersky has not disclosed the scale of victims, but warns that the group's shift to custom tools poses a significant threat. Recommendations for protection include monitoring specific Windows activities and restricting remote management functionalities.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline