Back to all lessons
Awareness Lessons
4 weeks ago

BambooToken Malware Hijacks Legitimate Software to Establish Covert C2 via MQTT

BambooToken exploits DLL sideloading through Tendyron's legitimate 'OnKey' software, demonstrating how trusted third-party applications can become attack vectors when not properly vetted or monitored. The use of the MQTT protocol for command-and-control is a deliberate evasion tactic, as MQTT traffic on ports 1883/8883 is often permitted through firewalls in IoT-heavy environments and blends with normal operational traffic. This multi-platform capability targeting both Windows and Linux systems broadens the attack surface significantly, making it harder for teams relying on OS-specific defenses to detect. The extended dwell time — active since at least February 2023 — highlights a critical failure in anomaly detection and threat hunting, allowing adversaries to operate undetected for years.

Tactical Insight

Immediate actions

  • Audit all third-party software installations (particularly Tendyron OnKey) and verify DLL integrity using application whitelisting tools.
  • Block or restrict outbound MQTT traffic (ports 1883 and 8883) at the perimeter firewall unless explicitly required for business operations.
  • Hunt for BambooToken indicators of compromise (IoCs) across both Windows and Linux endpoints using current threat intelligence feeds.

Long-term improvements

  • Implement a formal software supply chain vetting process that includes DLL sideloading risk assessment before approving any third-party application for enterprise use.
  • Enforce application whitelisting and DLL load order controls via solutions like Microsoft AppLocker or Windows Defender Application Control.
  • Establish a dedicated IoT/OT network segment that strictly controls and logs all MQTT broker communications.

Detection measures

  • Deploy behavioral detection rules in your SIEM to alert on unusual MQTT connections originating from non-IoT endpoints or user workstations.
  • Enable process-level logging (e.g., Sysmon on Windows, auditd on Linux) to capture DLL load events and correlate them against known-good baselines.
  • Integrate cross-platform EDR coverage to ensure Linux servers receive the same telemetry depth as Windows endpoints.