BambooToken Malware Hijacks Legitimate Software to Establish Covert C2 via MQTT
BambooToken exploits DLL sideloading through Tendyron's legitimate 'OnKey' software, demonstrating how trusted third-party applications can become attack vectors when not properly vetted or monitored. The use of the MQTT protocol for command-and-control is a deliberate evasion tactic, as MQTT traffic on ports 1883/8883 is often permitted through firewalls in IoT-heavy environments and blends with normal operational traffic. This multi-platform capability targeting both Windows and Linux systems broadens the attack surface significantly, making it harder for teams relying on OS-specific defenses to detect. The extended dwell time — active since at least February 2023 — highlights a critical failure in anomaly detection and threat hunting, allowing adversaries to operate undetected for years.
Tactical Insight
Immediate actions
- Audit all third-party software installations (particularly Tendyron OnKey) and verify DLL integrity using application whitelisting tools.
- Block or restrict outbound MQTT traffic (ports 1883 and 8883) at the perimeter firewall unless explicitly required for business operations.
- Hunt for BambooToken indicators of compromise (IoCs) across both Windows and Linux endpoints using current threat intelligence feeds.
Long-term improvements
- Implement a formal software supply chain vetting process that includes DLL sideloading risk assessment before approving any third-party application for enterprise use.
- Enforce application whitelisting and DLL load order controls via solutions like Microsoft AppLocker or Windows Defender Application Control.
- Establish a dedicated IoT/OT network segment that strictly controls and logs all MQTT broker communications.
Detection measures
- Deploy behavioral detection rules in your SIEM to alert on unusual MQTT connections originating from non-IoT endpoints or user workstations.
- Enable process-level logging (e.g., Sysmon on Windows, auditd on Linux) to capture DLL load events and correlate them against known-good baselines.
- Integrate cross-platform EDR coverage to ensure Linux servers receive the same telemetry depth as Windows endpoints.