Bleepingcomputer BambooToken Malware Exploits MQTT for Control of Infected Systems
Article Content
- •BambooToken malware uses MQTT for stealthy control of infected systems.
- •Active since February 2023, targeting sectors in Asia and South America.
- •Sideloading via Tendyron's OnKey software is a primary infection vector.
The BambooToken malware, discovered by Lumen's Black Lotus Labs, has been active since at least February 2023, targeting Windows and Linux systems across Asia and South America. It uses the MQTT protocol for command-and-control communications, allowing stealthy operations and evasion of detection. The malware was delivered by sideloading through Tendyron's OnKey USB token software, which is widely used in high-security environments. The campaign has infected various sectors, including mobile applications, legal services, and financial institutions. Recent telemetry indicates ongoing activity as of July 2026, with multiple compromised servers identified. Researchers found that the malware can perform extensive surveillance, including keylogging and audio recording, although some capabilities appear to be in development. The threat actor remains unidentified, but the targeting patterns suggest possible links to China-aligned operations. Organizations are urged to enhance their defenses against this emerging threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track GhostEmperor, BambooToken and Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…