Angry Birds: Toy Ghouls’ new toys

2026-09-12T08:53:08Z08f87519821683edbf5a8df95293d3dcfb9ebb6d34773633c7ec6135c91d21a8
APTAfricaAndroidDNS tunnelingElementFinTechGoogle Apps ScriptIsraelJavaScriptMQTTMatrixMiddle EastNode.jsTrueConfadwareaviationbackdoorcommand-and-controlcyber-espionageexploitindustrial control systemskernel-modemalwareproxy botnetrootkit

What happened

Kaspersky reporting highlights multiple 2026 campaigns involving backdoors, espionage tooling, rootkits, malware delivery through legitimate software, and exploitation of unpatched servers. Notable activity includes Toy Ghouls using MQTT and Matrix/Element for command and control, Mirage Kitten deploying Node.js and JavaScript malware against aviation and FinTech organizations, HoneyMyte deploying a kernel-level rootkit, and Head Mare exploiting an unpatched TrueConf server. Project CAV3RN uses Google Apps Script and DNS-based routing to conceal C2 traffic.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
08f87519821683edbf5a8df95293d3dcfb9ebb6d34773633c7ec6135c91d21a8
Enrichment time
2026-09-12T08:53:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Angry Birds: Toy Ghouls’ new toys · Baitaphish