TOY Ghouls, a financially motivated hacker group active since 2025, has developed a custom backdoor for Windows systems, attributed by Kaspersky. This backdoor operates in two versions using HiveMQ and Element for command-and-control (C2). The malware is delivered via Windows Remote Management and installs itself as a persistent service. Encrypting its configuration using ChaCha20-Poly1305, it ensures settings are machine-specific.
The HiveMQ version communicates through MQTT, while the Element version uses a direct command-line interface. Kaspersky has not disclosed the scale of victims, but warns that the group's shift to custom tools poses a significant threat. Recommendations for protection include monitoring specific Windows activities and restricting remote management functionalities.