Angry Birds: Toy Ghouls’ new toys
Overview
Kaspersky's GERT team has identified new backdoors linked to the hacking group known as Toy Ghouls. These backdoors utilize two distinct methods for command-and-control: one operates through the HiveMQ MQTT broker, while the other employs the Matrix-based Element messenger. This discovery raises alarms as it indicates the group's ongoing efforts to establish secure communication channels for their malicious activities. The use of these platforms suggests that the attackers may be adapting their techniques to evade detection, which could pose significant risks to organizations relying on these technologies. Understanding and mitigating this threat is crucial for enhancing cybersecurity measures against such evolving tactics.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: HiveMQ MQTT broker, Matrix-based Element messenger
- Action Required: Organizations should monitor their systems for unusual activity related to HiveMQ and Element, and implement security measures to detect and block unauthorized access.
- Timeline: Newly disclosed
Original Article Summary
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
Impact
HiveMQ MQTT broker, Matrix-based Element messenger
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should monitor their systems for unusual activity related to HiveMQ and Element, and implement security measures to detect and block unauthorized access.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware, Kaspersky.