THE article details the activities of a financially motivated hacker group known as Toy Ghouls, emphasizing their use of a custom backdoor malware for infiltrating Russian organizations. The backdoor, available in two versions, utilizes the HiveMQ MQTT broker and the Element messaging platform for command and control (C2) communication.
Key sections of the report elaborate on the malware's delivery method via Windows Remote Management, its installation process, and how it communicates sensitive system data back to the attackers. Important takeaways suggest that the group's shift from public tools to bespoke malware indicates a move towards more sophisticated and stealthy cyberattack techniques.
Furthermore, indicators of compromise, including specific file names, hashes, and registry keys associated with the malware, are provided to assist in identifying infections.