ToyMaker: Unveiling the Role of Initial Access Brokers in Ransomware Attacks

Red | Attack Report
Download PDF

In 2023, ToyMaker, an Initial Access Broker, breached a critical infrastructure network using a custom backdoor called LAGTOY. The actor harvested credentials and established persistence before handing off access to the Cactus ransomware group. Weeks later, Cactus conducted reconnaissance, deployed remote tools, and executed a ransomware attack. The operation shows coordinated collaboration between initial access brokers and ransomware operators.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox