ToyMaker: Unveiling the Role of Initial Access Brokers in Ransomware Attacks
Red | Attack Report
Download PDFIn 2023, ToyMaker, an Initial Access Broker, breached a critical infrastructure network using a custom backdoor called LAGTOY. The actor harvested credentials and established persistence before handing off access to the Cactus ransomware group. Weeks later, Cactus conducted reconnaissance, deployed remote tools, and executed a ransomware attack. The operation shows coordinated collaboration between initial access brokers and ransomware operators.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox