New BambooToken Malware Uses MQTT to Control Windows and Linux Systems
A previously unknown malware framework called BambooToken, active since at least 2023, has adopted the Message Queuing Telemetry Transport (MQTT) protocol to communicate with compromised Windows and Linux systems. Researchers at ESET and Lumen’s Black Lotus Labs have documented variants developed between 2024 and 2025 that target servers used by mobile apps, legal and financial services, and software development firms across Asia and South America.
How BambooToken Uses MQTT for Command-and-Control
While MQTT itself is not a novel technology, its use in BambooToken malware represents an uncommon approach to command-and-control communications. The protocol offers attackers a significant operational advantage: infected systems do not connect directly to the attacker’s infrastructure, which increases both evasion and resilience. Communications can also be asynchronous, ensuring the malware continues to function during temporary network disruptions. This follows a pattern similar to what CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks documented with other emerging threats targeting critical infrastructure.

Black Lotus Labs recovered evidence that BambooToken spreads through two primary methods: side-loading via digitally signed Tendyron OnKey USB-token software or by impersonating the Kingsoft Office productivity suite. The researchers identified strings in the code pointing to keylogging, clipboard theft, audio recording, webcam capturing, and screenshot capturing capabilities, though these were found in “dead code” and may not have been actively deployed.
Scope and Attribution of BambooToken Malware
Lumen’s telemetry identified approximately a dozen compromised enterprise entities, with the most affected servers associated with mobile application backend infrastructure. Targets included hotels, biomedical firms, law firms, a financial organization, and a cryptocurrency website in Lithuania. The researchers also discovered that attackers compromised a GitLab server in Hong Kong, creating a potential foothold for supply-chain attacks. In a related development, NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions highlighted similar tactics where attackers leverage compromised infrastructure to expand their reach.
The Linux variant, BambooToken version 2.1 (observed in December 2025), collects extensive system information, spawns command shells, and allows operators to upload, download, and delete files. However, Black Lotus Labs noted the Linux sample “still appeared to be under development.” Although researchers could not attribute the activity to a specific threat actor, the targeting patterns are consistent with China-aligned operations, and some activity may have targeted overseas Chinese users accessing mainland services through the SpeedCN VPN service.
المصدر: BleepingComputer