
Findings and evidence
Kaspersky GERT identifies two custom backdoor variants associated with Toy Ghouls: one communicates through an MQTT broker, while another uses a Matrix-based messaging service. The report compares their delivery, configuration and persistence artifacts.
Why it matters
The defensive question is whether a connection fits the device and process that made it. Combine service-installation records, executable provenance and network context before classifying traffic to an otherwise legitimate platform.
Scope and limits
The report concerns specific malicious clients. It does not imply that MQTT, Matrix or their legitimate users are inherently malicious.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-09-04. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.