Back to all lessons
Awareness Lessons
last month

Toy Ghouls Deploy MQTT and Matrix-Based Backdoors Against Russian Orgs

The Toy Ghouls threat group has significantly evolved its tooling, moving from commodity leaked ransomware builders to custom backdoors that abuse legitimate messaging infrastructure — specifically the HiveMQ MQTT broker and the Element messenger — for command and control communications. This matters because using trusted, widely-adopted protocols and platforms allows malicious C2 traffic to blend seamlessly with normal network activity, making detection extremely difficult with standard signature-based tools. Organizations that lack deep packet inspection, behavioral analytics, or strict egress filtering will likely miss these communications entirely. The group's evolution also signals increasing operational sophistication, meaning defenders must continuously reassess their threat models rather than relying on static indicators of compromise.

Tactical Insight

Immediate actions

  • Audit and restrict outbound connections to MQTT brokers (port 1883/8883) and messaging platforms like Element/Matrix unless explicitly required by business operations.
  • Deploy or update threat intelligence feeds to include known Toy Ghouls/Bearlyfy/Feral Wolf IOCs and block associated infrastructure at the perimeter.
  • Hunt for 'mqtt-bird-agent' and 'matrix-bird-agent' artifacts across endpoints using EDR tooling.

Long-term improvements

  • Implement strict egress filtering with an allowlist approach to prevent unauthorized use of third-party messaging or IoT broker services as C2 channels.
  • Adopt a zero-trust network architecture with micro-segmentation to limit lateral movement if a backdoor is successfully deployed.
  • Maintain a continuously updated asset inventory and baseline of approved network communications to rapidly detect anomalous connections.

Detection measures

  • Deploy behavioral analytics and network traffic analysis (NTA) tools capable of identifying C2 patterns within legitimate protocol traffic such as MQTT and HTTPS-based messaging APIs.
  • Establish alerting rules for processes making unexpected outbound connections to MQTT brokers or Matrix homeservers.
  • Conduct regular threat hunting exercises focused on living-off-the-land and protocol-abuse techniques used by financially motivated actors.