logo

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

ID: 70d3dae3-6654-5631-a457-7dd940b8851d

STIX ID: report--70d3dae3-6654-5631-a457-7dd940b8851d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-09-04

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Toy Ghouls, a financially motivated threat actor, developed two custom Windows backdoors (mqtt-bird-agent and matrix-bird-agent) that use HiveMQ MQTT and Element/Matrix infrastructure for C2; they are deployed via WinRM and include machine-bound encrypted configs, persistent Windows service options, telemetry reporting, and remote command execution—capabilities that support reconnaissance, lateral movement, payload staging, and ransomware deployment. Defenders are advised to monitor suspicious WinRM activity, new services, access to SynapseAgent/cplsupport ProgramData locations and specific registry keys, and unexpected MQTT or Matrix traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.