BleepingComputer reports that a previously unknown malware framework called BambooToken has been active since at least 2023 and uses the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. Variants developed between 2024 and 2025 used MQTT for command-and-control communications after compromising servers tied to mobile apps, legal and financial services, and software development.
MQTT typically uses a central broker and message channels called “topics” to connect publishers and subscribers. BambooToken assigns each infected machine a unique identifier and uses topic subscriptions to receive commands, while sending status and system information through the broker. This design avoids direct connections to attacker infrastructure and supports asynchronous communication during temporary network disruptions. ESET documented an unrelated MQTT backdoor called MQsTTang in 2023.
Lumen’s research arm, Black Lotus Labs, says BambooToken spread through side-loading with digitally signed Tendyron OnKey USB-token software or by impersonating Kingsoft Office. A plugin enumerates antivirus products and sends the results to command-and-control infrastructure. Researchers also found strings referring to keylogging, clipboard theft, audio recording, webcam capture, and screenshots, but said these were “dead code” and could not confirm that the modules were used.
The latest linked sample was BambooToken version 2.1, observed in December 2025 on Linux. It collects system information, can spawn a command shell, and supports file uploads, downloads, and deletion, although Black Lotus Labs said it appeared to be under development. Lumen identified approximately a dozen compromised enterprise entities, mostly in Asia and South America, and said targeting patterns were consistent with China-aligned operations, without attributing the activity to a specific actor.
Comments
0No comments yet. Be the first to comment.