Executive Summary
The financially motivated threat actor Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf) has shifted from public open-source tools to custom-developed backdoors in their 2026 'Angry Birds' campaign. Previously known for deploying GenieLocker ransomware, the group is now utilizing two sophisticated backdoors: one communicating via HiveMQ MQTT brokers and another via the Matrix-based Element messenger. These tools are primarily targeting Russian organizations, indicating a maturation in the group's technical capabilities.
The attack chain involves the use of Evil-WinRM and WinRM-fs for delivery, followed by the installation of the 'bird-agents'. These backdoors utilize unconventional C2 channels to evade traditional network monitoring, leveraging machine-bound encryption for configuration files and registry-based persistence. The transition to proprietary tooling suggests an intent for longer-term persistence and more resilient operations within compromised environments.
Key Details
Threat Name
Toy Ghouls Custom Backdoors
Affects
—
Adversary
Toy Ghouls Other Adversaries and Aliases: HoneyMyte; Mirage Kitten; Armored Likho
Malware/Tools
mqtt-bird-agent, matrix-bird-agent, GenieLocker, Babuk, LockBit, Evil-WinRM, WinRM-fs
