BambooToken Malware Uses MQTT to Control Windows and Linux Servers
A previously unknown malware framework called BambooToken has been active since at least 2023 and uses the Message Queue Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.
Variants developed between 2024 and 2025 used MQTT for command-and-control (C2) communications after compromising servers associated with mobile applications, legal and financial services, and software development.
How BambooToken Uses MQTT for Command and Control
MQTT is a lightweight messaging protocol designed primarily for Internet of Things (IoT) devices. Instead of relying on direct communication channels, it uses a central broker and channels called “topics” to relay messages from publishers to subscribers.
Although MQTT is not new, using it for malware command and control is unusual. In 2023, cybersecurity researchers documented an unrelated backdoor called MQsTTang that also used the protocol.
With BambooToken, an infected machine subscribes to a topic associated with a unique identifier. The attacker can then publish commands to that topic, which are executed on the compromised host.
The malware also publishes system information and status updates through MQTT brokers while receiving operator instructions through subscribed topics.

Source: Lumen
This architecture means infected systems do not need to connect directly to the attacker’s infrastructure, potentially improving evasion and resilience. MQTT communication can also be asynchronous, helping maintain operations during temporary network interruptions.
BambooToken Delivered Through Sideloading and Software Impersonation
A report released today by Black Lotus Labs, the research arm of Lumen, says BambooToken infected systems through DLL sideloading involving digitally signed Tendyron OnKey USB token software or by impersonating the Kingsoft Office productivity suite.
Researchers recovered a BambooToken plugin that enumerates antivirus products installed on infected hosts and sends the results to the C2 server.
They also found strings referencing keylogging, clipboard theft, audio recording, webcam capture, and screenshot capture. However, these references were found in “dead code,” so researchers cannot confidently determine whether the related module exists, was used during the attacks, or remains under development.

Source: Lumen
Linux BambooToken Variant Supports Remote Shells and File Operations
Researchers also discovered the latest malware potentially associated with the campaign: a Linux variant called BambooToken version 2.1, observed in December 2025.
The Linux malware uses MQTT to collect extensive system information and create command shells. These shells allow operators to upload, download, and delete files. However, Black Lotus Labs notes that “the Linux samples appear to still be in development.”
BambooToken Compromised Organizations in Asia and South America
Lumen telemetry identified approximately a dozen compromised corporate entities, primarily in Asia and South America. The victims included hotels, biomedical companies, law firms, financial institutions, and a Lithuanian cryptocurrency website.
The most frequently compromised servers were associated with the backend infrastructure of mobile applications.
Researchers also found compromised GitLab servers in Hong Kong, creating a potential foothold for supply chain attacks.
Lumen hypothesizes that some of the activity may have targeted overseas Chinese users accessing mainland services through the SpeedCN VPN service.
Although researchers did not attribute BambooToken activity to a specific threat actor or known activity cluster, the targeting pattern is consistent with a China-aligned operation.
Indicators of Compromise Released
Lumen shared indicators of compromise (IoCs) associated with the campaign to help defenders detect and block BambooToken activity.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



