Skip to content
BambooToken Malware Exploits MQTT for Control of Infected Systems

BambooToken Malware Exploits MQTT for Control of Infected Systems

First seen 15 Sep 2026, 17:06 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 17:55 UTC
  • BambooToken malware uses MQTT for stealthy control of infected systems.
  • Active since February 2023, targeting sectors in Asia and South America.
  • Sideloading via Tendyron's OnKey software is a primary infection vector.

The BambooToken malware, discovered by Lumen's Black Lotus Labs, has been active since at least February 2023, targeting Windows and Linux systems across Asia and South America. It uses the MQTT protocol for command-and-control communications, allowing stealthy operations and evasion of detection. The malware was delivered by sideloading through Tendyron's OnKey USB token software, which is widely used in high-security environments. The campaign has infected various sectors, including mobile applications, legal services, and financial institutions. Recent telemetry indicates ongoing activity as of July 2026, with multiple compromised servers identified. Researchers found that the malware can perform extensive surveillance, including keylogging and audio recording, although some capabilities appear to be in development. The threat actor remains unidentified, but the targeting patterns suggest possible links to China-aligned operations. Organizations are urged to enhance their defenses against this emerging threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2023-02-01
BambooToken malware first identified
Initial activity of the BambooToken malware detected, targeting Windows and Linux systems.
Lumen
2024-01-01
MQTT protocol adopted for command-and-control
BambooToken variants began using MQTT for communications, enhancing evasion tactics.
BleepingComputer
2025-12-01
Latest malware version discovered
Black Lotus Labs identified the latest version of BambooToken, indicating ongoing development.
BleepingComputer
2026-07-01
Ongoing activity confirmed
Telemetry from Lumen indicates continued infections and command-and-control activity.
The Hacker News
2026-09-15
Research findings published
Lumen's Black Lotus Labs released detailed findings on BambooToken, urging immediate action for defense.
Lumen

More articles in this cluster (3)

Following this threat?

Track GhostEmperor, BambooToken and Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed