Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Introducing ToyMaker

released on 2025-04-23 @ 10:13:00 PM
The initial access broker (IAB), whom Talos calls “ToyMaker” and assesses with medium confidence is a financially motivated threat actor, exploits vulnerable systems exposed to the internet. They deploy their custom-made backdoor we call “LAGTOY” and extract credentials from the victim enterprise. LAGTOY can be used to create reverse shells and execute commands on infected endpoints.