Bottom line: The Toy Ghouls group's new malware campaign poses a significant threat to Android users in the United States, China, and Japan.
What's happening: Kaspersky experts discovered two backdoors used by the Toy Ghouls group: one with HiveMQ MQTT broker as its command-and-control server and the other with the Matrix-based Element messenger.
What to do: Security leaders should ensure their organizations' Android devices are up-to-date with the latest security patches and monitor for suspicious activity.