Tag
high
threat
Toy Ghouls Deploying Custom HiveMQ and Matrix-Based Backdoors
1 rule 3 TTPs 1 IOCThe threat actor Toy Ghouls is using WinRM to deploy custom 'Bird' backdoors that utilize HiveMQ MQTT brokers and the Matrix protocol for C2, featuring machine-bound encrypted configurations.
Toy Ghouls
backdoors
persistence
winrm
c2
mqtt
1r
3t
1i
critical
advisory
Zbtlink Router Firmware Contains Embedded ENDLESSDOORS Implant
3 TTPs 1 CVEZbtlink router firmware ships with the ENDLESSDOORS remote-control implant, which runs as root, masquerades as a kernel process, and enables unauthenticated remote command execution.
PoC
Router Firmware +20
supply-chain
firmware
backdoors
remote-access-trojan
network-security
3t
1c
updated