BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
DarkDotWeb · Sep 16, 2026 · 4 min read · Original story

BambooToken Malware Uses MQTT to Control Windows and Linux

BambooToken Malware Uses MQTT to Control Windows and Linux

BambooToken malware has targeted Windows and Linux systems since 2023, using MQTT and Cloudflare to manage infected machines.

A previously undocumented malware family has been targeting Windows and Linux systems since at least 2023, using the MQTT messaging protocol to communicate with infected machines while routing parts of its infrastructure through Cloudflare.

The malware, dubbed BambooToken by researchers at Lumen’s Black Lotus Labs, has been observed in attacks against organizations across Asia and South America, with activity detected as recently as July 2026.

Black Lotus Labs discovered BambooToken samples on VirusTotal in early 2026. The researchers found that attackers were using legitimate software associated with Tendyron’s OnKey USB security tokens to load malicious components through DLL sideloading.

Tendyron’s OnKey software is designed to work with hardware-based security tokens used for authentication, including in financial and other high-security environments.

The researchers said there is no evidence that Tendyron’s code-signing certificate or build environment was compromised. Instead, the attackers appear to be taking advantage of software that is vulnerable to DLL sideloading on systems where the legitimate program is already installed.

BambooToken was also observed using modified components associated with Kingsoft Office in some activity.

One of the more unusual aspects of BambooToken is its use of Message Queuing Telemetry Transport, or MQTT, for command-and-control communications.

MQTT is a lightweight publish-subscribe protocol commonly used by IoT devices and other systems that need efficient messaging.

Rather than relying solely on conventional direct connections to a command server, BambooToken uses MQTT to communicate with its operators. The malware can receive instructions to load or stop plugins, terminate itself and disconnect from the command infrastructure.

Earlier versions extracted their command-and-control server from a DAT file or used a hard-coded server as a fallback.

Later versions expanded the malware’s capabilities and used MQTT as a central part of the communication system.

Black Lotus Labs found BambooToken targeting Windows systems before the malware expanded to Linux environments.

As of December 2025, researchers had identified a Linux version capable of operating on open-source platforms while continuing to use MQTT for command and control.

The malware gathers detailed information about compromised systems and can identify installed security software.

One Windows plugin uses Windows Management Instrumentation to collect information about antivirus products installed on the machine and sends the results back to the command server.

Researchers also identified additional code that suggests BambooToken may have been developed with broader surveillance capabilities in mind, although the presence of inactive code does not establish that those functions were actually used during the observed attacks.

Lumen identified approximately a dozen compromised organizations across Asia and South America.

The affected entities included companies connected to mobile applications, a hotel in Vietnam, a biomedical organization in Argentina, a legal firm in Chile, a cryptocurrency-related website in Lithuania and a Malaysian financial organization.

Researchers also identified a compromised GitLab server in Hong Kong.

Some of the infrastructure communicating with BambooToken’s command servers was associated with MikroTik and DrayTek routers in Singapore, Cambodia and Vietnam.

BambooToken’s operators also used Cloudflare as a proxy for parts of their command infrastructure.

According to Black Lotus Labs, domains associated with the campaign reached relatively high positions in Cloudflare Radar’s rankings during periods of activity. The researchers said this suggests the infrastructure was communicating with a substantial number of infected systems.

Using MQTT together with Cloudflare allows the operators to manage multiple compromised machines without relying on a conventional direct connection between every infected host and the attacker’s infrastructure.

Who Is Behind BambooToken? As of now the identity of the operators remains unknown.

Lumen said the use of DLL sideloading, combined with other infrastructure clues including a SoftEther VPN connection originating from a VPS, suggests a possible China nexus.

However, the researchers have not publicly attributed BambooToken to a specific threat group.

The targeting also appears consistent with a broader data-collection operation rather than a campaign focused solely on disrupting systems.

Black Lotus Labs said the compromised organizations could provide access to information such as financial transactions, travel histories and other sensitive data depending on the victim.

BambooToken’s continued activity through July 2026 shows that the malware remains an active threat, while its use of MQTT demonstrates how attackers continue to repurpose legitimate protocols to make command-and-control traffic harder to distinguish from normal network activity.

Source: The Hacker News

References in this story

  1. BambooToken Malware Uses MQTT to Control Windows and Linux Systems thehackernews.com BambooToken uses MQTT for C2 across Windows and Linux, with a dozen compromised entities detected in Asia and South America.

Markets in this story

Guides related to this story

← Back to all news