Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Angry Birds: Toy Ghouls’ new toys

Kaspersky documents Toy Ghouls deploying backdoors that abuse the HiveMQ MQTT broker and Matrix-based Element messenger as covert C2 channels — blending attack traffic into legitimate IoT and chat protocols.

Summary written by editorial AI · Source link below

Filed by Securelist (Kaspersky)1 min readRead at source ↗

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

Editorial Analysis

Why it matters

C2 traffic routed through legitimate IoT and messaging platforms evades traditional network defences, raising the bar for protocol-level detection in enterprise environments.

What to do

Review network egress policies to detect and alert on unexpected MQTT or Matrix protocol traffic from non-designated hosts.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Securelist (Kaspersky)

External link — opens at Securelist (Kaspersky) in a new tab.

§
Continue with

More from the Threat Intel Desk