Malware

BambooToken malware uses MQTT for stealthy command and control

As detailed in Bleeping Computer, a previously unknown malware framework named BambooToken, active since at least 2023, has been observed employing the Message Queuing Telemetry Transport (MQTT) protocol for command-and-control communications with both Windows and Linux systems.

The malware, which has been active since at least 2023, adopted MQTT for its command-and-control (C2) communications in variants developed between 2024 and 2025, according to a report by Black Lotus Labs. This method allows infected machines to subscribe to specific communication channels, or "topics," where attackers publish commands. The malware then publishes status updates and system information back through the same broker. This indirect communication model enhances evasion and resilience by preventing direct connections between infected systems and the attacker's infrastructure. BambooToken has been observed infecting systems through side-loading via digitally signed Tendyron OnKey USB-token software or by impersonating Kingsoft Office. While researchers have identified potential capabilities like keylogging and data exfiltration, some of these features were found in "dead code" and their active use is unconfirmed.

The campaign has targeted approximately a dozen enterprise entities, primarily in Asia and South America, including hotels, biomedical firms, law firms, a financial organization, and a cryptocurrency website. Compromised servers were often associated with the backend infrastructure of mobile applications, and a compromised GitLab server in Hong Kong presented a potential supply-chain attack vector. Although no specific threat actor has been identified, the targeting patterns are consistent with China-aligned operations.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds