Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
BambooToken Malware Exploits MQTT to Control Systems

BambooToken Malware Exploits MQTT to Control Systems

Posted on September 15, 2026 By CWS

Cybersecurity experts have unveiled a new cross-platform campaign that leverages the Message Queueing Telemetry Transport (MQTT) protocol to command and control both Windows and Linux systems. The malware, named BambooToken, has been active since at least February 2023, with its presence detected in regions across Asia and South America as recently as July 2026.

BambooToken’s Discovery and Initial Findings

Analysts at Lumen Black Lotus Labs identified the BambooToken malware on VirusTotal in early 2026, suggesting the work of a highly skilled threat actor who has managed to evade detection. Although the initial method of infiltration remains unidentified, the threat actor reportedly employed Tendyron’s ‘OnKey’ software to sideload malicious agents into targeted systems. Tendyron’s security tokens are widely used in high-security environments, particularly in China’s financial and government sectors.

Despite the lack of evidence indicating a breach of Tendyron’s code-signing certificate or build environment, experts suspect that the attackers exploit a vulnerability in the binary to execute DLL sideloading attacks. This allows the malware to infiltrate networks likely to have the program installed.

Technical Details and Attack Strategies

BambooToken utilizes MQTT, a lightweight protocol for remote command-and-control operations, a tactic not entirely new in the cyber threat landscape. Notably, the Chinese hacking group Mustang Panda previously employed a similar method with a backdoor called MQsTTang. The malware’s early versions extracted the command server details from a .DAT file, defaulting to a hard-coded server if necessary.

In later versions, the malware sideloads a rogue DLL to execute commands via MQTT, expanding its reach to Linux systems by December 2025. The initial version was activated through a PowerShell script, which allocated memory for the malicious code. This approach likely reduced detection by Endpoint Detection and Response (EDR) systems, prompting the evolution of the threat actor’s tactics.

Impact and Future Implications

BambooToken is designed to collect extensive host information and deploys an antivirus plugin on Windows systems. This plugin uses the Windows Management Instrumentation (WMI) framework to gather details about installed antivirus software and send them to a command server. The threat actors have used Cloudflare infrastructure to mask their operations, with domains linked to the campaign achieving notable traffic ranks on Cloudflare Radar.

Black Lotus Labs also reported identifying IP addresses in Singapore, Cambodia, and Vietnam interacting with active command servers. The compromised servers are linked to various sectors, including mobile applications, a GitLab server in Hong Kong, and a Vietnamese company developing lifestyle management devices.

The threat actor’s identity remains unknown, but the use of DLL sideloading and VPN connections suggests a potential Chinese origin. The emergence of both MQsTTang and BambooToken in early 2023 hints at possible inspiration from Mustang Panda’s tactics, allowing for enhanced malware capabilities using MQTT.

This campaign underscores the significant data collection potential of such malware, with implications for privacy and security. The targeting of mobile apps and financial organizations could enable detailed pattern-of-life analyses and expose sensitive transaction data, highlighting the urgent need for robust cybersecurity defenses.

The Hacker News Tags:Asia, BambooToken, Cloudflare, cyber threats, Cybersecurity, data collection, DLL Sideloading, Linux, Lumen Black Lotus Labs, Malware, MQsTTang, MQTT, South America, Tendyron, Windows

Post navigation

Previous Post: Critical WooCommerce Flaw Exploited by Hackers
Next Post: Vercel’s $1M Bug Bounty Reveals Linux Kernel Issues

Related Posts

MuddyWater Exploits Teams for Credential Theft in Covert Attack MuddyWater Exploits Teams for Credential Theft in Covert Attack The Hacker News
AI-Driven Browser Ransomware Exploits Chromium API AI-Driven Browser Ransomware Exploits Chromium API The Hacker News
UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud The Hacker News
DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer Endpoints DragonForce Exploits SimpleHelp Flaws to Deploy Ransomware Across Customer Endpoints The Hacker News
Microsoft Highlights AI Vulnerability to Tool Description Attacks Microsoft Highlights AI Vulnerability to Tool Description Attacks The Hacker News
Meta Thwarts NSO Group’s WhatsApp Phishing Scheme Meta Thwarts NSO Group’s WhatsApp Phishing Scheme The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Details 17 Hacker Tactics Targeting Active Directory
  • Exein Raises $270M for AI Security Expansion
  • Iranian Spyware Targets Journalists Via Telegram
  • Critical Telegram Desktop Bug Exposed Chat Data
  • Vercel’s $1M Bug Bounty Reveals Linux Kernel Issues

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Details 17 Hacker Tactics Targeting Active Directory
  • Exein Raises $270M for AI Security Expansion
  • Iranian Spyware Targets Journalists Via Telegram
  • Critical Telegram Desktop Bug Exposed Chat Data
  • Vercel’s $1M Bug Bounty Reveals Linux Kernel Issues

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark