Angry Birds: Toy Ghouls’ new toys愤怒的小鸟:玩具总动员的新玩具
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

SOC, TI and IR posts
Kaspersky Security Services
Indicators of compromise
We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker . In early July 2026, we observed the group using a custom backdoor for the first time.
We identified two versions of this backdoor: one uses the HiveMQ MQTT broker as its C2 server, while the other relies on the Element messenger. Both versions include “bird” in their names:
mqtt-bird-agent 0.1.0 (HiveMQ version)
matrix-bird-agent 0.1.0 (Element version)
This post examines how the backdoor is delivered to target systems, how it establishes persistence, and how it communicates with its C2 server.
In this campaign, the attackers use Windows Remote Management (WinRM) to deliver the backdoors and their configuration files to compromised systems. The group relies on open-source tools such as Evil-WinRM and WinRM-fs to do this.
The backdoor can both run within an interactive command-line session and establish persistence as a Windows service, using the --install or install option, depending on the backdoor version. The --service (or service ) option is not available by default and is instead used as an argument for the installed Windows service.
Other launch options are listed in the backdoor’s help output:
HiveMQ version backdoor help output
In the Element version, the backdoor help output looks as follows:
Element version backdoor help output
By default, the backdoor looks for a config.toml configuration file in the directory where the executable was launched, then falls back to %PROGRAMDATA%\SynapseAgent\config.toml (Element version) or %PROGRAMDATA%\cplsupport\config.toml (HiveMQ version). If no configuration file is found in either location, the full path can be specified using the -c (--config) option.
The backdoor accepts both unencrypted configuration files and files with partially encrypted sections. In the first case, once the backdoor is launched, it reads the file and partially encrypts it using the seal() function (the --seal option in the HiveMQ version), applying the ChaCha20-Poly1305 algorithm with a key derived from the value of the HKLM\Software\Microsoft\Cryptography\MachineGuid registry key. This means that after the backdoor’s first run, the configuration file becomes bound to that specific machine. On subsequent runs, the configuration is decrypted automatically. If the input configuration was already partially encrypted, it is likewise decrypted automatically.
If the configuration cannot be decrypted, the backdoor stops running.
Encrypted configuration files look as follows:
Encrypted backdoor configuration file, HiveMQ version
The encrypted portion of the HiveMQ version’s configuration contains the following parameters:
agent_privkey : the agent’s private key
channel_id : the channel identifier used to communicate with the broker
server_pubkey : the server’s public key
Decrypted blob field in the HiveMQ version’s configuration
In the Element version, the configuration file is deleted immediately after the first run, and the relevant parameters are instead written to the HKLM\Software\synapse\Config\SealedConfig registry key. On subsequent runs, the backdoor checks the registry for its configuration first.
Decrypted Element version configuration file, retrieved from the registry
The Element version’s configuration specifies the address of an Element server controlled by the attackers, a room identifier, and an access_token used to access that room. If this parameter is left empty, the backdoor prompts for the password interactively during installation. After successfully creating a session, the backdoor saves the received token to the blob field.
At startup, both backdoor versions send a GET request to http://ip-api.com/json to determine the system’s public IP address and country of origin.
The first version uses the public HiveMQ MQTT broker ( broker.hivemq.com ) as its C2 server. The free tier of this broker supports up to 100 concurrent connections and up to 10 GB of traffic per month. The attackers set up their own cluster and used it both to collect telemetry from compromised systems and to send commands to the backdoor.
Once a connection is established, the system’s status is sent via a POST request to broker . hivemq . com : 8883 / [ cluster_id ] / status . The message format is: { "online" : bool , "hostname" : "hostname.domain" , "timestamp" : unix_timestamp , "location" : { "json" } } .
At intervals defined in the configuration file, system information, such as CPU load and available memory, is sent via a POST request to broker . hivemq . com : 8883 / [ cluster_id ] / metrics3 . The message format is: { cpu _ percent ":float," mem_used _ bytes ":int," mem_total _ bytes ":int," disk_used _ bytes ":int," disk_total _ bytes ":int," load _ 1m ":float," load _ 5m ":float," load _ 15m ":float," uptime _ secs ":int," hostname ":" hostname . domain "," timestamp " : unix_timestamp } .
The backdoor sends GET requests to broker . hivemq . com : 8883 / [ cluster_id ] / cmd / req to retrieve commands from the C2 server. The server responds in the format: { "cmd_id" : int , "command" : "str" , "timeout_secs" : int } .
Commands are executed via PowerShell.exe in hidden mode, using the -NonInteractive -NoProfile -Command parameters.
Command execution results are sent to the command server at broker . hivemq . com : 8883 / [ cluster_id ] / cmd / res in the { "stdout" : "str" , "stderr" : "str" , "exit_code" : int , "duration_ms" : int } format.
For the second backdoor version, the attackers set up their own Element server running on the Matrix protocol, meet.element[.]tw , as the C2 server. On this server, they created a room used to receive messages containing device information and to send commands for execution on the compromised system. The communication flow is as follows:
Once a connection is successfully established, the backdoor sends an m.bird.status message containing the system’s status. This message format is identical to that used in the HiveMQ version.
At intervals defined in the configuration file, information about the compromised system is sent as an m.bird.metrics message. Field names are slightly different from those in the first version: { cpu_percent _ x100 ":float," mem_used _ bytes ":int," mem_total _ bytes ":int," disk_used _ bytes ":int," disk_total _ bytes ":int," load_1m _ x100 ":float," load_5m _ x100 ":float," load_15m _ x100 ":float," uptime _ secs ":int," hostname ":" hostname . domain "," timestamp " : unix_timestamp } .
This version of the backdoor supports two types of commands, distinguished by the start of the received message. To set a new interval for sending metrics, the attackers send a message beginning with config:set_interval (accepting values from 5 to 3600 seconds). The new value is saved to the HKLM\Software\SynapseAgent\metrics_interval registry key. Messages containing commands to execute begin with the string cmd: . Based on data extracted from Element’s SQLite databases on the compromised system, we were able to identify the account name the attackers used to send commands: panel-bot .
To set a new interval for sending metrics, the attackers send a message beginning with config:set_interval (accepting values from 5 to 3600 seconds). The new value is saved to the HKLM\Software\SynapseAgent\metrics_interval registry key.
Messages containing commands to execute begin with the string cmd: . Based on data extracted from Element’s SQLite databases on the compromised system, we were able to identify the account name the attackers used to send commands: panel-bot .
Received commands are executed via the Windows command line interface.
Command output is sent as an m.bird.cmd_response message. This message format mirrors the one used in the HiveMQ version.
We have been tracking Toy Ghouls’ activity for quite some time. We previously found that the group had expanded its arsenal with a custom ransomware strain, GenieLocker, and we have now discovered that it has also developed a backdoor capable of giving it full control over an infected device. The new tools use unconventional channels to communicate with their C2 server: the HiveMQ MQTT broker and the Matrix-based Element messenger. This shift away from publicly available open-source projects toward custom-built tools suggests that Toy Ghouls is working to make its attacks more sophisticated and to evade detection for longer.
Kaspersky security solution verdicts:
HEUR:Backdoor.Win64.Suptoml.gen
HEUR:Trojan.Script.Zapchast.conf
Backdoor.Win64.Agent.smgdvy
Trojan.Script.Zapchast.abwm
Trojan.Win64.Agent.smgsfo
Trojan.Script.Zapchast.abwo
File names and MD5 hashes:
cplsupport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 )
wtass.exe ( 7916C33688385525078BEE504C90F359 )
HKLM\Software\synapse\Config\SealedConfig
HKLM\Software\SynapseAgent\metrics_interval
cplsupport (Problem Reports Control Panel)
wtas (Windows Telemetry Aggregator Service)
broker.hivemq.com (a legitimate resource used by cybercriminals)
ip-api.com (a legitimate resource used by cybercriminals)
Malware Technologies
Malware Descriptions
Angry Birds: Toy Ghouls’ new toys
This site uses Akismet to reduce spam. Learn how your comment data is processed.
From the same authors
Anatomy of a Cyber World Global Report 2026
Goodbye, dark Telegram: Blocks are pushing the underground out
Inside the dark web job market
Signal in the noise: what hashtags reveal about hacktivism in 2025
Incident response analyst report 2024
In the same category
An analysis of incidents at Brazilian educational institutions
Risk reduction redefined: How compromise assessment helps strengthen cyberdefenses
Whispers from the Dark Web Cave. Cyberthreats in the Middle East
A deep dive into the most interesting incident response cases of last year
Tusk: unraveling a complex infostealer campaign
SOC、TI 和 IR 职位
卡巴斯基安全服务
妥协的迹象
我们持续追踪 Toy Ghouls(又名 Bearlyfy、Laboo.boo 和 Feral Wolf)的活动。该组织以牟利为目的,自 2025 年以来一直以俄罗斯组织为攻击目标。攻击者最初完全依赖于从 GitHub 公共代码库中提取的工具,以及泄露的 Babuk 和 LockBit 勒索软件构建器,后来转向使用他们自己开发的定制勒索软件 GenieLocker。2026 年 7 月初,我们首次观察到该组织使用了定制的后门程序。
我们发现了两种版本的后门:一种使用 HiveMQ MQTT 代理作为其 C2 服务器,另一种则依赖于 Element 消息传递程序。这两个版本的名称中都包含“bird”字样:
mqtt-bird-agent 0.1.0(HiveMQ 版本)
matrix-bird-agent 0.1.0(元素版本)
本文探讨了后门如何被传递到目标系统,如何建立持久性,以及如何与其 C2 服务器通信。
在此次攻击活动中,攻击者利用 Windows 远程管理 (WinRM) 将后门程序及其配置文件传播到受感染的系统。该组织依赖 Evil-WinRM 和 WinRM-fs 等开源工具来实现这一目标。
该后门程序既可以在交互式命令行会话中运行,也可以通过 `--install` 或 `install` 选项(具体取决于后门程序版本)以 Windows 服务的形式持久运行。`--service`(或 `service`)选项默认情况下不可用,而是作为已安装 Windows 服务的参数使用。
后门程序的帮助输出中列出了其他启动选项:
HiveMQ 版本后门帮助输出
在 Element 版本中,后门帮助输出如下所示:
元素版本后门帮助输出
默认情况下,后门程序会在可执行文件启动的目录中查找 config.toml 配置文件,如果找不到,则会回退到 %PROGRAMDATA%\SynapseAgent\config.toml(Element 版本)或 %PROGRAMDATA%\cplsupport\config.toml(HiveMQ 版本)。如果在这两个位置都找不到配置文件,则可以使用 -c (--config) 选项指定完整路径。
该后门程序既接受未加密的配置文件,也接受部分加密的配置文件。对于未加密的配置文件,后门程序启动后,会读取该文件并使用 seal() 函数(HiveMQ 版本中的 --seal 选项)对其进行部分加密,加密算法为 ChaCha20-Poly1305,密钥取自 HKLM\Software\Microsoft\Cryptography\MachineGuid 注册表项的值。这意味着后门程序首次运行后,配置文件将绑定到该特定机器。在后续运行中,配置文件将自动解密。如果输入的配置文件已经部分加密,也会自动解密。
如果配置无法解密,后门程序将停止运行。
加密后的配置文件如下所示:
加密后门配置文件,HiveMQ 版本
HiveMQ 版本配置的加密部分包含以下参数:
agent_privkey:代理的私钥
channel_id:用于与代理通信的通道标识符
server_pubkey:服务器的公钥
已解密的 HiveMQ 版本配置中的 blob 字段
在 Element 版本中,配置文件会在首次运行后立即删除,相关参数则会写入 HKLM\Software\synapse\Config\SealedConfig 注册表项。后续运行时,后门程序会首先检查注册表中的配置信息。
从注册表中检索到的已解密 Element 版本配置文件
Element 版本的配置指定了攻击者控制的 Element 服务器地址、房间标识符以及用于访问该房间的 access_token。如果此参数为空,后门会在安装过程中以交互方式提示输入密码。成功创建会话后,后门会将接收到的令牌保存到 blob 字段中。
启动时,这两个后门版本都会向 http://ip-api.com/json 发送 GET 请求,以确定系统的公共 IP 地址和来源国家/地区。
第一版使用公共 HiveMQ MQTT 代理(broker.hivemq.com)作为其 C2 服务器。该代理的免费套餐支持最多 100 个并发连接和每月最多 10 GB 的流量。攻击者搭建了自己的集群,并利用该集群从受感染的系统中收集遥测数据,同时向后门发送命令。
连接建立后,系统状态将通过 POST 请求发送到 broker.hivemq.com:8883/[cluster_id]/status。消息格式为:{"online": bool, "hostname": "hostname.domain", "timestamp": unix_timestamp, "location": {"json"}}。
在配置文件中定义的时间间隔内,系统信息(例如 CPU 负载和可用内存)通过 POST 请求发送到 broker.hivemq.com:8883/[cluster_id]/metrics3。消息格式为:{ cpu_percent ":float," mem_used_bytes ":int," mem_total_bytes ":int," disk_used_bytes ":int," disk_total_bytes ":int," load_1m ":float," load_5m ":float," load_15m ":float," uptime_secs ":int," hostname ":" hostname.domain "," timestamp ": unix_timestamp }。
后门向 broker.hivemq.com:8883/[cluster_id]/cmd/req 发送 GET 请求,以从 C2 服务器检索命令。服务器以如下格式响应:{"cmd_id": int, "command": "str", "timeout_secs": int}。
命令通过 PowerShell.exe 以隐藏模式执行,使用 -NonInteractive -NoProfile -Command 参数。
命令执行结果以 { "stdout" : "str", "stderr" : "str", "exit_code" : int, "duration_ms" : int } 格式发送到 broker.hivemq.com:8883/[cluster_id]/cmd/res 的命令服务器。
对于第二个后门版本,攻击者搭建了自己的 Element 服务器(运行在 Matrix 协议上,地址为 meet.element[.]tw)作为 C2 服务器。他们在该服务器上创建了一个房间,用于接收包含设备信息的消息,并发送命令在受感染的系统上执行。通信流程如下:
连接成功建立后,后门会发送一条包含系统状态的 m.bird.status 消息。该消息格式与 HiveMQ 版本中使用的消息格式相同。
在配置文件中定义的时间间隔内,有关受感染系统的信息将以 m.bird.metrics 消息的形式发送。字段名称与第一个版本略有不同:{ cpu_percent _ x100 ":float," mem_used _ bytes ":int," mem_total _ bytes ":int," disk_used _ bytes ":int," disk_total _ bytes ":int," load_1m _ x100 ":float," load_5m _ x100 ":float," load_15m _ x100 ":float," uptime _ secs ":int," hostname ":" hostname . domain "," timestamp " : unix_timestamp }。
此版本的后门支持两种类型的命令,可通过接收消息的开头来区分。要设置新的指标发送间隔,攻击者会发送一条以 `config:set_interval` 开头的消息(接受 5 到 3600 秒之间的值)。新值会保存到注册表项 `HKLM\Software\SynapseAgent\metrics_interval` 中。包含要执行的命令的消息以字符串 `cmd:` 开头。根据从受感染系统上的 Element SQLite 数据库中提取的数据,我们能够识别出攻击者用于发送命令的帐户名:`panel-bot`。
为了设置新的指标发送间隔,攻击者会发送一条以 config:set_interval 开头的消息(接受 5 到 3600 秒之间的值)。新值会被保存到 HKLM\Software\SynapseAgent\metrics_interval 注册表项中。
包含要执行的命令的消息以字符串“cmd:”开头。根据从受感染系统上的 Element SQLite 数据库中提取的数据,我们能够识别攻击者用于发送命令的帐户名:panel-bot。
接收到的命令通过 Windows 命令行界面执行。
命令输出以 m.bird.cmd_response 消息的形式发送。此消息格式与 HiveMQ 版本中使用的格式相同。
我们已追踪 Toy Ghouls 的活动一段时间了。此前我们发现该组织已扩充其攻击手段,开发出一种名为 GenieLocker 的定制勒索软件。现在我们又发现,他们还开发了一种后门程序,能够完全控制受感染的设备。这些新工具使用非常规渠道与其 C2 服务器通信:HiveMQ MQTT 代理和基于 Matrix 的 Element 即时通讯工具。这种从公开开源项目转向定制工具的转变表明,Toy Ghouls 正在努力使其攻击更加复杂,并延长其逃避检测的时间。
卡巴斯基安全解决方案评测结果:
HEUR:后门.Win64.Suptoml.gen
HEUR:Trojan.Script.Zapchast.conf
后门.Win64.Agent.smgdvy
Trojan.Script.Zapchast.abwm
Trojan.Win64.Agent.smgsfo
Trojan.Script.Zapchast.abwo
文件名和MD5哈希值:
cplsupport.exe ( BFADBEEE63A4F0BF19EC9DEB8FA58F58 )
wtass.exe ( 7916C33688385525078BEE504C90F359 )
HKLM\Software\synapse\Config\SealedConfig
HKLM\Software\SynapseAgent\metrics_interval
cplsupport(问题报告控制面板)
wtas(Windows遥测聚合服务)
broker.hivemq.com(一个被网络犯罪分子利用的合法资源)
ip-api.com(一个被网络犯罪分子利用的合法资源)
恶意软件技术
恶意软件描述
愤怒的小鸟:玩具总动员的新玩具
本网站使用 Akismet 来减少垃圾邮件。了解您的评论数据如何处理。
出自同一作者之手
网络世界剖析:2026年全球报告
再见了,黑暗的Telegram:街区正在将地下空间挤出去
暗网就业市场内部
噪声中的信号:话题标签揭示了2025年黑客行动主义的哪些信息
2024年事件响应分析报告
同一类别
对巴西教育机构事件的分析
风险降低的新定义:入侵评估如何帮助加强网络防御
来自暗网洞穴的低语:中东的网络威胁
深入剖析去年最有趣的事件响应案例
《獠牙》:揭开一场复杂的窃取信息活动