In early August, we reported that APT group Labooboo (Toy Ghouls, Bearlyfy, Feral Wolf) created its own backdoor, which uses non-standard methods to communicate with a command server: the Matrix-based messenger Element and the HiveMQ MQTT broker.
We promised to publish the details later. Here they are: in the article "Angry Birds: Toy Ghouls’ new toys" our experts took a detailed look at how this backdoor is delivered to target systems, how it establishes persistence, and how it interacts with the C2 server.
And here, for brevity, we will add only a list of indicators of compromise that you can look for in your systems:
File names and MD5:
- cplsupport.exe (BFADBEEE63A4F0BF19EC9DEB8FA58F58)
- wtass.exe (7916C33688385525078BEE504C90F359)
- config.toml
Registry keys:
- HKLM\Software\synapse\Config\SealedConfig
- HKLM\Software\SynapseAgent\metrics_interval
Service names:
- cplsupport (Problem Reports Control Panel)
- wtas (Windows Telemetry Aggregator Service)
Domain names:
- meet.element[.]tw
- broker.hivemq.com (legitimate resource used by attackers)
- ip-api.com (legitimate resource used by attackers)
