[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0rQVSsZK0YbUH7t1U4WafubwLjo_y5lPEaxhZOj3cps":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"c28f3aff-2a29-4529-9383-c1d3f137c1c0","BambooToken Malware Uses MQTT to Control Windows and Linux Systems","bambootoken-malware-uses-mqtt-to-control-windows-and-linux-systems-999d56","Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.","A new multi-platform malware family, dubbed BambooToken, has been discovered actively targeting organizations in Asia and South America since at least February 2023. The malware utilizes the MQTT protocol for command-and-control (C2) and employs a DLL sideloading technique involving Tendyron's 'OnKey' software to gain initial access. Activity has been observed as recently as July 2026, with samples frequently uploaded from Chinese IP addresses.","BambooToken malware uses MQTT for C2, targets Windows and Linux systems in Asia and South America.","BambooToken Malware Uses MQTT to Control Windows and Linux Systems Ravie LakshmananSep 15, 2026 Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America. Activity linked to the malware has been detected as recently as July 2026. Lumen Black Lotus Labs said it discovered the previously undocumented malware on VirusTotal in early 2026, with evidence pointing to a skilled threat actor that has managed to stay undetected until now. The initial access vector used to deliver BambooToken remains undetermined. \"The actor used Tendyron's 'OnKey' software to sideload agents into targeted machines,\" Black Lotus Labs said in a report shared with The Hacker News. \"Tendyron creates hardware-based tokens employed in high-security settings to verify user identities for workstation access. Their website lists customers in China's financial and government sectors, among other verticals\" Tendyron OnKey is a second-generation Public Key Infrastructure (PKI) USB security token and authentication device designed to protect online banking and financial transactions. On its website, Tendyron claims to have 190 million tokens in circulation. Although neither Tendyron's code-signing certificate nor its build environment has been compromised in connection with the activity, it's suspected that the operators are relying on binary that's vulnerable to DLL sideloading to trigger the attack within targeted networks that are likely to have the program installed. In addition, most of the BambooToken samples have been uploaded to the VirusTotal platform from the Chinese IP address space, indicating a data collection campaign targeting users within and other neighboring countries. The use of MQTT, a lightweight, publish-subscribe network protocol, for remote command-and-control (C2) is not a new phenomenon. As far back as January 2023, the Chinese nation-state hacking group known as Mustang Panda was observed using a backdoor called MQsTTang that used the IoT messaging protocol to fetch and execute commands on compromised hosts. Besides MQsTTang, there have been only a handful of campaigns that have used MQTT to date - An Android malware called Tizi that can harvest sensitive data from various messaging and social media apps, as well as use HTTPS or MQTT for C2 to realize its goals. A malware loader called WailingCrab (aka WikiLoader) that's distributed via delivery- and shipping-themed email messages. It's attributed to a cybercrime group called Bamboo Spider. An operational technology (OT) malware called IOCONTROL (aka OrpaCrab) that has targeted IoT and SCADA systems in Israel and the U.S. Early iterations of the BambooToken agent work by extracting the C2 server from a .DAT file, or falling back to a hard-coded server if the file is not found. Once this step is complete, the malware proceeds to gather system details and transmit them to the C2 server (\"chat5188[.]tk\"). In response, the server issues commands to load a plugin, stop all plugins, terminate the execution of the malware, and disconnect from the C2 server. Subsequent versions of the malware sideload a rogue version of a DLL (\"OnKeyToken_KEB.dll\") used by the Tendyron OnKeySrv program to enumerate the host and enter into a command loop that uses MQTT for C2. As of December 2025, BambooToken has expanded in scope to also target Linux hosts while still relying on MQTT. \"The first version of BambooToken was initiated via a PowerShell script,\" Ryan English, information security engineer at Lumen Technologies Black Lotus Labs, told The Hacker News. \"The PowerShell script would act as a 'stager' by allocating memory and then running the malicious file. We assess that sideloading would likely trigger fewer EDR alerts, so as the campaign evolved so did that threat actors TTPs.\" BambooToken is equipped to collect extensive host information and deliver an antivirus plugin for Windows that uses the Windows Management Instrumentation (WMI) framework to gather details about installed antivirus products on the machine and exfiltrate them to the C2 server (\"api80.c2iznja[.]com\"). \"The domains used Cloudflare as a proxy for their infrastructure,\" Black Lotus Labs said. \"One domain associated with the 2025 campaign recently entered the top 500,000 domains on Cloudflare Radar. The older domain ranked in the top 1 million at the peak of operations in 2024, indicating widespread infection across campaigns for this activity cluster.\" The threat research arm of Lumen also said it identified IP addresses geolocated to Singapore, Cambodia, and Vietnam communicating with one of the active C2 nodes. These IP addresses correspond to MikroTik and DrayTek routers. In addition, a dozen compromised entities have been detected in Asia and South America. The vast majority of the compromised servers are associated with mobile applications, as well as a GitLab server in Hong Kong and a Vietnamese company developing a portable lifestyle management device. Other targets include a hotel in Vietnam, a biomedical company in Argentina, a legal firm in Chile, a cryptocurrency website in Lithuania and a Malaysian finance organization. It's unknown at this stage who is behind the activity. But the use of DLL sideloading, coupled with a SoftEther VPN connection originating from a Virtual Private Server (VPS) to one of the C2 nodes, suggests a China nexus. Another interesting aspect worth mentioning is that both MQsTTang and BambooToken emerged around the same time in early 2023. While there is no evidence of any overlap between the two threat activity clusters, Lumen said it's possible the threat actor could have taken a leaf out of the Mustang Panda playbook to update its own malware to support MQTT in the upcoming versions. \"Using MQTT to control numerous clients from a central point, combined with routing via Cloudflare, enables large-scale operation through an unconventional communication method,\" Lumen concluded. \"We believe this campaign's targeting supports extensive data collection. Mobile apps and smartwatches connected to cellular networks could enable pattern-of-life analysis; targeting financial organizations might expose transaction data, and attacking hospitality systems could reveal travel history and plans.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  linux, Malware, network security, Windows ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microso","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fbambootoken-malware-uses-mqtt-to.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEj7hFIl_GRAlPuegwLGZ2PzXVsPEUTEevpEYhkU2Va9isB7aC8a0jJCLVszVOUc_CAIb4IkIkmRjkvyaTIadUizNNEhHTxvzlPX0EUN6UQutjyrauyi35fzRtBjFudyOW4HlAnTRNC9XDj39uNBMKUWHUV2g0Rt8o3aSADZAeAIYgLN-dT0q8gIH9cWUDBF\u002Fs1600\u002Fwindows-linux.jpg","2026-09-15T15:23:19+00:00","2026-09-15T16:00:35.232465+00:00",8,[18,21,24,27],{"name":19,"type":20},"OnKey","product",{"name":22,"type":23},"Tendyron","vendor",{"name":25,"type":26},"MQTT","technology",{"name":28,"type":29},"Bamboo Spider","threat_actor","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":30,"icon":32,"name":33,"slug":34},null,"Malware","malware",[36,41,46,48],{"category":37},{"id":38,"icon":32,"name":39,"slug":40},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":42},{"id":43,"icon":32,"name":44,"slug":45},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":47},{"id":30,"icon":32,"name":33,"slug":34},{"category":49},{"id":50,"icon":32,"name":51,"slug":52},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[54,58,62],{"type":55,"value":56,"context":57},"domain","chat5188.tk","BambooToken C2 server",{"type":59,"value":60,"context":61},"hash_sha256","a1b2c3d4e5f67890a1b2c3d4e5f67890a1b2c3d4e5f67890a1b2c3d4e5f67890","Example hash for BambooToken agent (placeholder)",{"type":59,"value":63,"context":64},"f0e9d8c7b6a54321f0e9d8c7b6a54321f0e9d8c7b6a54321f0e9d8c7b6a54321","Example hash for rogue DLL (placeholder)"]