Cybersecurity experts have unveiled a new cross-platform campaign that leverages the Message Queueing Telemetry Transport (MQTT) protocol to command and control both Windows and Linux systems. The malware, named BambooToken, has been active since at least February 2023, with its presence detected in regions across Asia and South America as recently as July 2026.
BambooToken’s Discovery and Initial Findings
Analysts at Lumen Black Lotus Labs identified the BambooToken malware on VirusTotal in early 2026, suggesting the work of a highly skilled threat actor who has managed to evade detection. Although the initial method of infiltration remains unidentified, the threat actor reportedly employed Tendyron’s ‘OnKey’ software to sideload malicious agents into targeted systems. Tendyron’s security tokens are widely used in high-security environments, particularly in China’s financial and government sectors.
Despite the lack of evidence indicating a breach of Tendyron’s code-signing certificate or build environment, experts suspect that the attackers exploit a vulnerability in the binary to execute DLL sideloading attacks. This allows the malware to infiltrate networks likely to have the program installed.
Technical Details and Attack Strategies
BambooToken utilizes MQTT, a lightweight protocol for remote command-and-control operations, a tactic not entirely new in the cyber threat landscape. Notably, the Chinese hacking group Mustang Panda previously employed a similar method with a backdoor called MQsTTang. The malware’s early versions extracted the command server details from a .DAT file, defaulting to a hard-coded server if necessary.
In later versions, the malware sideloads a rogue DLL to execute commands via MQTT, expanding its reach to Linux systems by December 2025. The initial version was activated through a PowerShell script, which allocated memory for the malicious code. This approach likely reduced detection by Endpoint Detection and Response (EDR) systems, prompting the evolution of the threat actor’s tactics.
Impact and Future Implications
BambooToken is designed to collect extensive host information and deploys an antivirus plugin on Windows systems. This plugin uses the Windows Management Instrumentation (WMI) framework to gather details about installed antivirus software and send them to a command server. The threat actors have used Cloudflare infrastructure to mask their operations, with domains linked to the campaign achieving notable traffic ranks on Cloudflare Radar.
Black Lotus Labs also reported identifying IP addresses in Singapore, Cambodia, and Vietnam interacting with active command servers. The compromised servers are linked to various sectors, including mobile applications, a GitLab server in Hong Kong, and a Vietnamese company developing lifestyle management devices.
The threat actor’s identity remains unknown, but the use of DLL sideloading and VPN connections suggests a potential Chinese origin. The emergence of both MQsTTang and BambooToken in early 2023 hints at possible inspiration from Mustang Panda’s tactics, allowing for enhanced malware capabilities using MQTT.
This campaign underscores the significant data collection potential of such malware, with implications for privacy and security. The targeting of mobile apps and financial organizations could enable detailed pattern-of-life analyses and expose sensitive transaction data, highlighting the urgent need for robust cybersecurity defenses.
