Kaspersky discovers new backdoors from the Toy Ghouls group
Kaspersky GERT experts have identified new malicious tools used by the Toy Ghouls group.

Experts from Kaspersky's GERT team have recently discovered new backdoors actively used by the group named Toy Ghouls.
According to what was detected by the security specialists, these cyber threats exploit different communication channels for their activities. Specifically, one version of the backdoor uses the HiveMQ MQTT broker as a command and control server.
Another identified variant, on the other hand, relies on the Element messaging system, based on the Matrix protocol, to manage the same control functions.
