#LAGTOY
Cisco Talos has published a profile on ToyMaker, an initial access broker who compromises victims and sells access to data extortion groups, such as the Cactus ransomware group

They are also the developers of a backdoor known as LAGTOY (or HOLERUN).

blog.talosintelligence.com/introducing-...
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs
Cisco Talos discovered a sophisticated attack on critical infrastructure by ToyMaker and Cactus, using the LAGTOY backdoor to orchestrate a relentless double extortion scheme.
blog.talosintelligence.com
April 24, 2025 at 9:46 AM
We just published our investigation into a Cactus ransomware campaign, uncovering TOYMAKER, an IAB group using a custom backdoor LAGTOY. It’s still challenging to identify compartmentalized attacks. We’ll share our approach and solutions at @pivotcon.bsky.social in 2 weeks! #toymaker
Talos uncovered a major compromise in a critical infrastructure enterprise by an IAB, ToyMaker, and a double extortion gang, Cactus.

Learn how ToyMaker infiltrates vulnerable systems: blog.talosintelligence.com/introducing-toymaker-an-initial-access-broker
April 24, 2025 at 1:26 PM
ToyMaker, an IAB, sells organizational access to the CACTUS ransomware gang. Using LAGTOY malware, they exploit vulnerabilities, steal credentials, enabling double extortion attacks. Motivation is purely financial.#ToyMakerRansomware
April 26, 2025 at 8:35 PM
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs buff.ly/PxBJ6PE
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs
Cisco Talos discovered a sophisticated attack on critical infrastructure by ToyMaker and Cactus, using the LAGTOY backdoor to orchestrate a relentless double extortion scheme.
buff.ly
April 24, 2025 at 8:12 AM
Кукловодът от даркнет: Докато сте актуализирали Windows, ToyMaker вече е продал паролите ви на конкуренцията

Cisco Talos разкрива „бизнес стратегията“ на един опасен особено опасен брокер на данни. В света на киберпрестъпността има нов опасен играч: Cisco Talos разкри схемата на работа на брокер…
Кукловодът от даркнет: Докато сте актуализирали Windows, ToyMaker вече е продал паролите ви на конкуренцията
Cisco Talos разкрива „бизнес стратегията“ на един опасен особено опасен брокер на данни. В света на киберпрестъпността има нов опасен играч: Cisco Talos разкри схемата на работа на брокер на първичен достъп под псевдонима ToyMaker. Атакуващият продава компрометирани системи на рансъмуер оператори за изнудване, по-конкретно на групата CACTUS. Хакерът използва специално разработения зловреден софтуер LAGTOY, известен също като HOLERUN, който създава реверсивни шелове и изпълнява почти произволни команди на заразените устройства. Заплахата е докладвана за първи път в края на март 2023 г. в отчетите на …
www.kaldata.com
April 28, 2025 at 6:26 AM
揭秘ToyMaker利用LAGTOY恶意软件向CACTUS勒索软件集团出售初始访问权限实现双重勒索

https://qian.cx/posts/47F9ED40-C2B8-4185-A8B9-DD63C11E494E
May 9, 2025 at 4:19 PM
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
thehackernews.com/2025/04/toym...
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
ToyMaker deploys LAGTOY malware to steal credentials and sell access to CACTUS ransomware groups for double extortion.
thehackernews.com
April 26, 2025 at 1:10 PM
Как ToyMaker использует LAGTOY для продажи доступа группировкам вымогателей CACTUS с целью двойного вымогательства

https://kripta.biz/posts/68FF1CCB-7A52-47BC-8301-3FD3D6718439
May 9, 2025 at 4:20 PM
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
thehackernews.com
April 26, 2025 at 1:14 PM
ToyMaker’s Playbook: Cisco Talos Exposes IAB Tactics Leading to Cactus Ransomware
ToyMaker's Playbook: Cisco Talos Exposes IAB Tactics Leading to Cactus Ransomware
Cisco Talos uncovers ToyMaker's IAB activity, paving the way for Cactus ransomware. Learn how LAGTOY backdoor & credential theft led to a major breach.
securityonline.info
April 25, 2025 at 3:03 AM
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion

Cybersecurity researchers have detailed the activities of an initial access broker (IAB) dubbed ToyMaker that has been observed handing over access to double extortion ransomware gangs like CACTU…

#hackernews #news
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
Cybersecurity researchers have detailed the activities of an initial access broker (IAB) dubbed ToyMaker that has been observed handing over access to double extortion ransomware gangs like CACTUS. The IAB has been assessed with medium confidence to be a financially motivated threat actor, scanning for vulnerable systems and deploying a custom malware called LAGTOY (aka HOLERUN). "LAGTOY can be
thehackernews.com
April 27, 2025 at 7:37 PM
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
Details: thehackernews.com/2025/04/toym...
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
ToyMaker deploys LAGTOY malware to steal credentials and sell access to CACTUS ransomware groups for double extortion.
thehackernews.com
April 28, 2025 at 6:39 AM
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs
blog.talosintelligence.com/introducing-...
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangs
Cisco Talos discovered a sophisticated attack on critical infrastructure by ToyMaker and Cactus, using the LAGTOY backdoor to orchestrate a relentless double extortion scheme.
blog.talosintelligence.com
April 26, 2025 at 9:40 AM
ToyMaker’s Playbook: Cisco Talos Exposes IAB Tactics Leading to Cactus Ransomware
Details: securityonline.info/toymakers-pl...
ToyMaker's Playbook: Cisco Talos Exposes IAB Tactics Leading to Cactus Ransomware
Cisco Talos uncovers ToyMaker's IAB activity, paving the way for Cactus ransomware. Learn how LAGTOY backdoor & credential theft led to a major breach.
securityonline.info
April 25, 2025 at 6:18 AM
Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs
blog.talosintelligence.com/introducing-...
Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs
Cisco Talos discovered a sophisticated attack on critical infrastructure by ToyMaker and Cactus, using the LAGTOY backdoor to orchestrate a relentless double extortion scheme.
blog.talosintelligence.com
April 23, 2025 at 10:29 AM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Saturday, April 26, 2025
ToyMaker Uses LAGTOY to Sell Access to CACTUS Ransomware Gangs for Double Extortion
ToyMaker deploys LAGTOY malware to steal credentials and sell access to CACTUS ransomware groups for double extortion.
thehackernews.com
April 27, 2025 at 5:38 AM
Feed: "Cisco Talos Blog"
By: Joey Chen on Wednesday, April 23, 2025
Introducing ToyMaker, an Initial Access Broker working in cahoots with double extortion gangs
Cisco Talos discovered a sophisticated attack on critical infrastructure by ToyMaker and Cactus, using the LAGTOY backdoor to orchestrate a relentless double extortion scheme.
blog.talosintelligence.com
April 23, 2025 at 6:07 PM