← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

Toy Ghouls backdoors complicate trust in ordinary network services

Kaspersky GERT identifies two custom backdoor variants associated with Toy Ghouls: one communicates through an MQTT broker, while another uses a Matrix-based messaging service.

Source published 2026-09-04Threat researchResearch briefing
Original publication preview: Toy Ghouls backdoors complicate trust in ordinary network services
Kaspersky / Securelist ↗

Findings and evidence

Kaspersky GERT identifies two custom backdoor variants associated with Toy Ghouls: one communicates through an MQTT broker, while another uses a Matrix-based messaging service. The report compares their delivery, configuration and persistence artifacts.

Why it matters

The defensive question is whether a connection fits the device and process that made it. Combine service-installation records, executable provenance and network context before classifying traffic to an otherwise legitimate platform.

Scope and limits

The report concerns specific malicious clients. It does not imply that MQTT, Matrix or their legitimate users are inherently malicious.

Primary source

Kaspersky / Securelist: original publication. Source published 2026-09-04. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC