Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

BambooToken Malware Campaign Leverages MQTT Protocol to Compromise Global Infrastructure Across Windows and Linux Systems

Cahyo Dewo, September 16, 2026

Cybersecurity researchers have uncovered a sophisticated and long-running multi-platform espionage campaign dubbed BambooToken, which utilizes the Message Queueing Telemetry Transport (MQTT) protocol to maintain covert command-and-control (C2) communication with infected Windows and Linux environments. First identified by the threat intelligence arm of Lumen Technologies, Black Lotus Labs, the malware has been active since at least February 2023. By exploiting the inherent trust placed in legitimate software through DLL sideloading, the operators behind BambooToken have successfully infiltrated diverse sectors, including government entities, financial institutions, and specialized technology firms across Asia and South America.

The Mechanics of the BambooToken Infiltration

The core of the BambooToken threat lies in its innovative use of MQTT, a lightweight messaging protocol typically reserved for Internet of Things (IoT) devices and machine-to-machine communication. Because MQTT traffic is often permitted through corporate firewalls and is frequently overlooked by traditional signature-based intrusion detection systems, it serves as an ideal conduit for exfiltrating sensitive data and receiving remote commands without raising alarms.

The infection chain frequently involves the abuse of Tendyron’s "OnKey" software. Tendyron, a manufacturer of second-generation Public Key Infrastructure (PKI) USB security tokens, provides hardware-based authentication solutions heavily utilized in high-security environments, including Chinese government and financial sectors. While there is no evidence that Tendyron’s internal build environment or code-signing certificates have been compromised, the attackers rely on the presence of vulnerable, legitimate binaries within the software package. By placing a malicious DLL—specifically "OnKeyToken_KEB.dll"—within the application’s directory, the attackers force the legitimate software to load the malicious code upon execution, a classic yet highly effective technique known as DLL sideloading.

Chronology of Activity

The operational timeline of BambooToken reveals a deliberate evolution in tactics, techniques, and procedures (TTPs).

BambooToken Malware Uses MQTT to Control Windows and Linux Systems
  • February 2023: The inception of the BambooToken campaign is recorded. Early iterations focused primarily on Windows systems, using PowerShell scripts to act as stagers for the malicious payload.
  • January 2024: The campaign gains momentum, with C2 domains associated with the malware achieving high visibility on platforms like Cloudflare Radar, indicating a significant increase in the number of compromised hosts.
  • December 2025: The threat actors demonstrate technical agility by expanding their reach to Linux-based systems, ensuring that the malware’s cross-platform capabilities allow for broader network infiltration.
  • Early 2026: Lumen Black Lotus Labs identifies samples of the malware on the VirusTotal analysis platform. This discovery marks the first public acknowledgment of the campaign, which had previously operated in the shadows.
  • July 2026: Continued activity is detected, confirming that the threat actor remains operational despite increased scrutiny from the cybersecurity community.

Technical Analysis and Command-and-Control Architecture

In its early stages, BambooToken agents were configured to extract C2 server information from local .DAT files, providing a degree of modularity in their communication. When these files were absent, the malware defaulted to hard-coded server addresses. The primary C2 domain, "chat5188[.]tk," served as the initial hub for tasking.

As the malware matured, the operators shifted to more sophisticated infrastructure, including the use of Cloudflare as a proxy to obfuscate the true location of their C2 nodes. Furthermore, the inclusion of a specialized antivirus plugin demonstrates a high level of operational maturity. By leveraging the Windows Management Instrumentation (WMI) framework, the malware can systematically identify installed security products, allowing the attackers to tailor their subsequent actions to avoid detection by specific EDR (Endpoint Detection and Response) solutions.

The shift toward Linux targeting in late 2025 further highlights the campaign’s focus on server-side infrastructure. By targeting Git repositories and specialized management devices, the attackers gain a strategic vantage point, enabling them to move laterally within networks that might otherwise be protected from standard malware.

Geographical and Sector-Specific Targeting

The geographic distribution of the campaign is extensive, with a clear concentration of compromised assets in the Asia-Pacific region and South America. Forensic analysis of IP traffic points to infected devices in Singapore, Cambodia, and Vietnam, often routed through common networking hardware such as MikroTik and DrayTek routers.

The target list is notably diverse, suggesting a campaign focused on high-value intelligence gathering rather than indiscriminate disruption. Identified victims include:

BambooToken Malware Uses MQTT to Control Windows and Linux Systems
  • Financial Institutions: In Malaysia and other regions, where the theft of transaction data remains a primary objective.
  • Government and Legal Entities: Targeted for the potential to extract confidential documentation and state-level communications.
  • Technology and Infrastructure: Developers of portable lifestyle devices and GitLab server administrators in Hong Kong, indicating a potential interest in intellectual property and software supply chain access.
  • Hospitality: Hotels in Vietnam, which may provide attackers with access to the travel itineraries and personal identifying information (PII) of high-profile guests.

Broader Implications and Security Analysis

The emergence of BambooToken is symptomatic of a broader trend in cyber-espionage: the weaponization of legitimate, trusted software to bypass defensive perimeters. By leveraging DLL sideloading and unconventional protocols like MQTT, threat actors are effectively rendering traditional perimeter defenses—such as simple IP blocking—largely ineffective.

"Using MQTT to control numerous clients from a central point, combined with routing via Cloudflare, enables large-scale operation through an unconventional communication method," stated researchers at Black Lotus Labs. The implication is that security teams must adopt a more nuanced approach to network monitoring. Standard traffic analysis may fail to distinguish between legitimate IoT telemetry and the command-and-control signals of a sophisticated threat actor.

Furthermore, the potential for "pattern-of-life" analysis is a significant concern. By compromising mobile applications and smart devices that constantly sync with cellular networks, the operators behind BambooToken are likely building detailed profiles on their targets. This type of data collection is invaluable for long-term espionage, as it allows attackers to anticipate the physical and digital movements of high-value individuals.

The China Nexus and Future Outlook

While attribution remains difficult in the realm of advanced persistent threats (APTs), the technical fingerprints left by the BambooToken operators point toward a China-based threat actor. The use of SoftEther VPN, a protocol frequently observed in Chinese-origin campaigns, and the deployment of infrastructure that mirrors the tactics of groups like Mustang Panda—specifically regarding the use of MQTT—suggest a sophisticated, well-resourced adversary.

It is possible that the BambooToken operators observed the success of the MQsTTang backdoor, first documented in early 2023, and adapted their own toolset to incorporate similar messaging protocols. This "copycat" or parallel-development behavior suggests an ongoing arms race where threat actors continuously refine their TTPs based on the public disclosure of competitor activities.

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

As the campaign continues into the latter half of 2026, the primary challenge for enterprises lies in the detection of "low and slow" threats. Organizations that utilize Tendyron hardware or other PKI-based authentication devices should conduct thorough audits of their endpoints, specifically looking for anomalous DLL loads and unauthorized outbound traffic over MQTT ports.

In conclusion, BambooToken represents a significant evolution in stealthy command-and-control operations. Its ability to pivot between Windows and Linux environments, coupled with its reliance on legitimate administrative tools, makes it a formidable challenge for even the most robust security operations centers. As intelligence continues to be gathered, the cybersecurity industry remains focused on identifying the specific motives behind this sustained campaign and developing the necessary countermeasures to neutralize its influence in the global digital landscape.

Cybersecurity & Digital Privacy acrossbambootokencampaigncompromiseCybercrimeGlobalHackingInfrastructureleverageslinuxmalwaremqttPrivacyprotocolSecuritysystemswindows

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes