Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 1 actor

LAGTOY

LAGTOY is a custom backdoor malware family used by the financially motivated initial access actor ToyMaker and identified by Mandiant as the same malware family as HOLERUN, which has been associated with UNC961. Talos reported ToyMaker exploiting known vulnerable internet-facing systems to gain access to high-value targets, including critical infrastructure organizations, then deploying LAGTOY on infected Windows endpoints. The malware is used to create reverse shells and execute commands on compromised machines, enabling post-compromise access and credential theft operations prior to access handoff to downstream ransomware actors such as Cactus. In the reported 2023 intrusion, ToyMaker used Magnet RAM Capture to dump memory, archived the dumps with 7za.exe, exfiltrated them with pscp.exe, and likely harvested credentials before later access was used by Cactus.

Talos reported that LAGTOY was persisted as a Windows service named "WmiPrvSV". It communicates with a hard-coded command-and-control server over TCP port 443 using raw sockets rather than TLS, includes anti-debugging logic via kernel32!SetUnhandledExceptionFilter(), and supports command handling including codes such as "#pt", "#pd", and "#ps". Talos also assessed with high confidence that LAGTOY contains novel time-based execution logic unique to the malware family. Additional reported behavior includes contacting a hard-coded C2 server to retrieve commands, creating processes, and running commands under specified users with corresponding privileges. Mandiant reported that the malware can process three commands from its C2 with an 11,000 millisecond sleep interval between them.

High-confidence associations in the content tie LAGTOY/HOLERUN to ToyMaker, UNC961, and follow-on ransomware activity involving Cactus; Talos also noted public reporting that UNC961 activity has preceded Maze and Egregor deployments by distinct follow-on actors. Known indicators and artifacts directly mentioned in the content include the Windows service name "WmiPrvSV", raw-socket C2 over port 443, and the malware alias HOLERUN.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ToyMaker

Talos tracked an IAB named ToyMaker and disclosed that the threat actor uses a homegrown backdoor called LAGTOY to steal victims’ credentials.

via medium s2wblogmedium.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1078Valid AccountsEvidence1

Talos tracked an IAB named ToyMaker and disclosed that the threat actor uses a homegrown backdoor called LAGTOY to steal victims’ credentials. ToyMaker, which used the LAGTOY backdoor to create a reverse shell, subsequently passed on access to secondary threat actors, most notably the Cactus group.

T1190Exploit Public-Facing ApplicationEvidence2

ToyMaker usually infiltrates an organization's environment by successfully exploiting a known vulnerability in an unpatched internet-facing server.

Persistence

2 techniques
T1078Valid AccountsEvidence1

Talos tracked an IAB named ToyMaker and disclosed that the threat actor uses a homegrown backdoor called LAGTOY to steal victims’ credentials. ToyMaker, which used the LAGTOY backdoor to create a reverse shell, subsequently passed on access to secondary threat actors, most notably the Cactus group.

T1543Create or Modify System ProcessEvidence1

LAGTOY is persisted on the system by creating a service for it [T1543]: sc create WmiPrvSV start= auto error= ignore binPath= C:\Program Files\Common Files\Services\WmiPrvSV.exe

Privilege Escalation

2 techniques
T1078Valid AccountsEvidence1

Talos tracked an IAB named ToyMaker and disclosed that the threat actor uses a homegrown backdoor called LAGTOY to steal victims’ credentials. ToyMaker, which used the LAGTOY backdoor to create a reverse shell, subsequently passed on access to secondary threat actors, most notably the Cactus group.

T1543Create or Modify System ProcessEvidence1

LAGTOY is persisted on the system by creating a service for it [T1543]: sc create WmiPrvSV start= auto error= ignore binPath= C:\Program Files\Common Files\Services\WmiPrvSV.exe

Stealth

1 technique
T1078Valid AccountsEvidence1

Talos tracked an IAB named ToyMaker and disclosed that the threat actor uses a homegrown backdoor called LAGTOY to steal victims’ credentials. ToyMaker, which used the LAGTOY backdoor to create a reverse shell, subsequently passed on access to secondary threat actors, most notably the Cactus group.

Discovery

1 technique
T1082System Information DiscoveryEvidence1

tasklist System Information Discovery [ T1082 ] quser System Information Discovery [ T1082 ] ipconfig /all System Information Discovery [ T1082 ]

INDICATORS OF COMPROMISE

IOCs tracked for this family

16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
8 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
8 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
ip.v4●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching16

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.