Cybersecurity researchers have identified an initial access broker (IAB) named ToyMaker, which is known for providing access to double extortion ransomware gangs, including CACTUS. This IAB is assessed with medium confidence as a financially motivated threat actor, actively scanning for vulnerable systems and utilizing a custom malware called LAGTOY (also known as HOLERUN). The activities of ToyMaker highlight the ongoing threats posed by IABs in the cybersecurity landscape, emphasizing the need for enhanced defensive measures against such actors.