Toy Ghouls Angry Birds Backdoor Campaign
Score: 8/10

Toy Ghouls Angry Birds Backdoor Campaign

Toy Ghouls (Bearlyfy) is using new custom backdoors, mqtt-bird-agent and matrix-bird-agent, targeting Russian organizations via HiveMQ and Element C2 channels.

Executive Summary

The financially motivated threat actor Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf) has shifted from public open-source tools to custom-developed backdoors in their 2026 'Angry Birds' campaign. Previously known for deploying GenieLocker ransomware, the group is now utilizing two sophisticated backdoors: one communicating via HiveMQ MQTT brokers and another via the Matrix-based Element messenger. These tools are primarily targeting Russian organizations, indicating a maturation in the group's technical capabilities.

The attack chain involves the use of Evil-WinRM and WinRM-fs for delivery, followed by the installation of the 'bird-agents'. These backdoors utilize unconventional C2 channels to evade traditional network monitoring, leveraging machine-bound encryption for configuration files and registry-based persistence. The transition to proprietary tooling suggests an intent for longer-term persistence and more resilient operations within compromised environments.

Key Details

Threat Name

Toy Ghouls Custom Backdoors

Affects

—

Adversary

Toy Ghouls Other Adversaries and Aliases: HoneyMyte; Mirage Kitten; Armored Likho

Malware/Tools

mqtt-bird-agent, matrix-bird-agent, GenieLocker, Babuk, LockBit, Evil-WinRM, WinRM-fs

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth8

Sources