Angry Birds: Toy Ghouls’ new toys
2026-09-12T08:53:08Z•08f87519821683edbf5a8df95293d3dcfb9ebb6d34773633c7ec6135c91d21a8
APTAfricaAndroidDNS tunnelingElementFinTechGoogle Apps ScriptIsraelJavaScriptMQTTMatrixMiddle EastNode.jsTrueConfadwareaviationbackdoorcommand-and-controlcyber-espionageexploitindustrial control systemskernel-modemalwareproxy botnetrootkit
What happened
Kaspersky reporting highlights multiple 2026 campaigns involving backdoors, espionage tooling, rootkits, malware delivery through legitimate software, and exploitation of unpatched servers. Notable activity includes Toy Ghouls using MQTT and Matrix/Element for command and control, Mirage Kitten deploying Node.js and JavaScript malware against aviation and FinTech organizations, HoneyMyte deploying a kernel-level rootkit, and Head Mare exploiting an unpatched TrueConf server. Project CAV3RN uses Google Apps Script and DNS-based routing to conceal C2 traffic.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 08f87519821683edbf5a8df95293d3dcfb9ebb6d34773633c7ec6135c91d21a8
- Enrichment time
- 2026-09-12T08:53:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.