Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
BambooToken Malware Exploits MQTT to Control Systems

BambooToken Malware Exploits MQTT to Control Systems

Posted on September 15, 2026 By CWS

Cybersecurity experts have unveiled a new cross-platform campaign that leverages the Message Queueing Telemetry Transport (MQTT) protocol to command and control both Windows and Linux systems. The malware, named BambooToken, has been active since at least February 2023, with its presence detected in regions across Asia and South America as recently as July 2026.

BambooToken’s Discovery and Initial Findings

Analysts at Lumen Black Lotus Labs identified the BambooToken malware on VirusTotal in early 2026, suggesting the work of a highly skilled threat actor who has managed to evade detection. Although the initial method of infiltration remains unidentified, the threat actor reportedly employed Tendyron’s ‘OnKey’ software to sideload malicious agents into targeted systems. Tendyron’s security tokens are widely used in high-security environments, particularly in China’s financial and government sectors.

Despite the lack of evidence indicating a breach of Tendyron’s code-signing certificate or build environment, experts suspect that the attackers exploit a vulnerability in the binary to execute DLL sideloading attacks. This allows the malware to infiltrate networks likely to have the program installed.

Technical Details and Attack Strategies

BambooToken utilizes MQTT, a lightweight protocol for remote command-and-control operations, a tactic not entirely new in the cyber threat landscape. Notably, the Chinese hacking group Mustang Panda previously employed a similar method with a backdoor called MQsTTang. The malware’s early versions extracted the command server details from a .DAT file, defaulting to a hard-coded server if necessary.

In later versions, the malware sideloads a rogue DLL to execute commands via MQTT, expanding its reach to Linux systems by December 2025. The initial version was activated through a PowerShell script, which allocated memory for the malicious code. This approach likely reduced detection by Endpoint Detection and Response (EDR) systems, prompting the evolution of the threat actor’s tactics.

Impact and Future Implications

BambooToken is designed to collect extensive host information and deploys an antivirus plugin on Windows systems. This plugin uses the Windows Management Instrumentation (WMI) framework to gather details about installed antivirus software and send them to a command server. The threat actors have used Cloudflare infrastructure to mask their operations, with domains linked to the campaign achieving notable traffic ranks on Cloudflare Radar.

Black Lotus Labs also reported identifying IP addresses in Singapore, Cambodia, and Vietnam interacting with active command servers. The compromised servers are linked to various sectors, including mobile applications, a GitLab server in Hong Kong, and a Vietnamese company developing lifestyle management devices.

The threat actor’s identity remains unknown, but the use of DLL sideloading and VPN connections suggests a potential Chinese origin. The emergence of both MQsTTang and BambooToken in early 2023 hints at possible inspiration from Mustang Panda’s tactics, allowing for enhanced malware capabilities using MQTT.

This campaign underscores the significant data collection potential of such malware, with implications for privacy and security. The targeting of mobile apps and financial organizations could enable detailed pattern-of-life analyses and expose sensitive transaction data, highlighting the urgent need for robust cybersecurity defenses.

The Hacker News Tags:Asia, BambooToken, Cloudflare, cyber threats, Cybersecurity, data collection, DLL Sideloading, Linux, Lumen Black Lotus Labs, Malware, MQsTTang, MQTT, South America, Tendyron, Windows

Post navigation

Previous Post: Critical WooCommerce Flaw Exploited by Hackers
Next Post: Vercel’s $1M Bug Bounty Reveals Linux Kernel Issues

Related Posts

Critical Vulnerabilities Found in vm2 Library Critical Vulnerabilities Found in vm2 Library The Hacker News
U.S. Sanctions Funnull for 0M Romance Baiting Scams Tied to Crypto Fraud U.S. Sanctions Funnull for $200M Romance Baiting Scams Tied to Crypto Fraud The Hacker News
Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls The Hacker News
CISO’s Guide To Web Privacy Validation And Why It’s Important CISO’s Guide To Web Privacy Validation And Why It’s Important The Hacker News
APT28 Exploits MSHTML Vulnerability Before February 2026 Patch APT28 Exploits MSHTML Vulnerability Before February 2026 Patch The Hacker News
Banking Malware Targets Windows and Android Devices Banking Malware Targets Windows and Android Devices The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Releases Major Security Update Fixing 273 Vulnerabilities
  • CISA Details 17 Hacker Tactics Targeting Active Directory
  • Exein Raises $270M for AI Security Expansion
  • Iranian Spyware Targets Journalists Via Telegram
  • Critical Telegram Desktop Bug Exposed Chat Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Releases Major Security Update Fixing 273 Vulnerabilities
  • CISA Details 17 Hacker Tactics Targeting Active Directory
  • Exein Raises $270M for AI Security Expansion
  • Iranian Spyware Targets Journalists Via Telegram
  • Critical Telegram Desktop Bug Exposed Chat Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark