Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
ID: 70d3dae3-6654-5631-a457-7dd940b8851d
STIX ID: report--70d3dae3-6654-5631-a457-7dd940b8851d
Feed Name: GBHackers
Toy Ghouls, a financially motivated threat actor, developed two custom Windows backdoors (mqtt-bird-agent and matrix-bird-agent) that use HiveMQ MQTT and Element/Matrix infrastructure for C2; they are deployed via WinRM and include machine-bound encrypted configs, persistent Windows service options, telemetry reporting, and remote command execution—capabilities that support reconnaissance, lateral movement, payload staging, and ransomware deployment. Defenders are advised to monitor suspicious WinRM activity, new services, access to SynapseAgent/cplsupport ProgramData locations and specific registry keys, and unexpected MQTT or Matrix traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
