Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Messaging Services for Windows Backdoors

Hackers Exploit Messaging Services for Windows Backdoors

Posted on September 4, 2026 By CWS

A financially driven cybercriminal group known as Toy Ghouls has developed two tailored Windows backdoors that utilize popular messaging platforms for command and control. These tools allow for covert command execution, system information collection, and sustained control over compromised devices.

Shift in Strategy for Toy Ghouls

This campaign represents a strategic shift for Toy Ghouls, which previously relied on publicly available tools and leaked ransomware builders. The adoption of custom malware indicates an effort to remain undetected within victim networks for extended periods.

Security researchers at Securelist identified the new malware in early July 2026, linking it to Toy Ghouls, also known as Bearlyfy, Laboo.boo, and Feral Wolf. The group has targeted Russian organizations since 2025 and is associated with the GenieLocker ransomware.

Technical Details of the Backdoors

The newly identified backdoors, named mqtt-bird-agent 0.1.0 and matrix-bird-agent 0.1.0, are deployed post-intrusion, demonstrating how initial breaches can evolve into severe network compromises. According to a Kaspersky report to Cyber Security News (CSN), these tools offer complete control over infected Windows systems.

Toy Ghouls employs Windows Remote Management (WinRM) to install these backdoors and their configurations on compromised systems. They use Evil-WinRM and WinRM-fs to facilitate file transfers and remote command execution.

Maintaining Persistence and Mitigation Strategies

Both backdoor versions can operate interactively or as Windows services, ensuring persistence even after reboots. This feature heightens the threat, as attackers can regain access despite the termination of the original remote session.

The malware encrypts its configuration in a way specific to the infected system. The Element variant removes its configuration file after initial use, transferring data to the Windows registry to minimize detectable artifacts.

Security teams are advised to audit WinRM access, restrict it to approved systems, and scrutinize unusual remote PowerShell activity. Monitoring for unexpected services such as cplsupport or wtas and suspicious configuration files in ProgramData folders is crucial.

Implications for Cybersecurity

The case underlines the necessity of viewing remote-management credentials as high-value assets, warranting robust authentication measures. Recent attacks highlight the dangers posed by the combination of social engineering and trusted Windows tools.

Despite the misuse of MQTT and Element protocols by Toy Ghouls, these services themselves are not inherently malicious. The situation exemplifies how threat actors exploit legitimate technologies to obfuscate command traffic and maintain control over compromised systems.

Security operations centers should remain vigilant and update detection capabilities to identify quiet backdoor activities, which often precede more overt ransomware operations.

Cyber Security News Tags:Cybersecurity, Element protocol, Kaspersky, Malware, messaging services, MQTT, network security, Toy Ghouls, Windows backdoors, WinRM

Post navigation

Previous Post: Critical Flaws in VMware Workstation and Fusion Addressed
Next Post: Phishing Attack Evades Filters Using Invisible Unicode

Related Posts

Top 10 Best Mobile Application Penetration Testing Companies in 2025 Top 10 Best Mobile Application Penetration Testing Companies in 2025 Cyber Security News
Hackers Exploit Government Sites for Malware Distribution Hackers Exploit Government Sites for Malware Distribution Cyber Security News
UNC3753 Targets US Law Firms with Vishing Tactics UNC3753 Targets US Law Firms with Vishing Tactics Cyber Security News
Phishing Scheme Exploits Dropbox to Steal User Credentials Phishing Scheme Exploits Dropbox to Steal User Credentials Cyber Security News
Miggo Security Named a Gartner® Cool Vendor in AI Security Miggo Security Named a Gartner® Cool Vendor in AI Security Cyber Security News
Burger King Uses DMCA Complaint to Take Down Blog Post Detailing Security Flaws on Drive-Thru Systems Burger King Uses DMCA Complaint to Take Down Blog Post Detailing Security Flaws on Drive-Thru Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026
  • Hackers Exploit Unicode to Bypass Phishing Filters

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026
  • Hackers Exploit Unicode to Bypass Phishing Filters

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark