VMTech
Discuss a project

BambooToken campaign controls Windows and Linux systems over MQTT

BambooToken campaign controls Windows and Linux systems over MQTT

Lumen Black Lotus Labs has disclosed BambooToken, a previously undocumented malware family that uses the Message Queueing Telemetry Transport (MQTT) protocol for command-and-control communication with Windows and Linux systems. The campaign has been active since at least February 2023, was detected as recently as July 2026, and has affected organizations in Asia and South America.

Researchers found BambooToken samples on VirusTotal in early 2026. Most samples were uploaded from Chinese IP address space, a pattern Black Lotus Labs said points to a data-collection campaign focused on users in China and neighbouring countries. The researchers have not attributed the activity to a specific actor.

DLL sideloading through OnKey software

The operators used Tendyron's OnKey software to sideload agents onto targeted machines. Tendyron OnKey is a second-generation PKI USB security token and authentication device used to protect online banking and financial transactions. Tendyron says 190 million tokens are in circulation.

Black Lotus Labs said there is no evidence that Tendyron's code-signing certificate or build environment was compromised. Instead, the attackers are suspected of exploiting a binary vulnerable to DLL sideloading in networks where the software is already installed. Later BambooToken variants sideload a rogue OnKeyToken_KEB.dll used by the OnKeySrv program, enumerate the host and enter an MQTT-based command loop.

MQTT channel and expanding capabilities

Early BambooToken agents obtain a command-and-control address from a .DAT file, falling back to a hard-coded server when the file is absent. They gather system information and send it to chat5188[.]tk. The server can instruct the implant to load or stop plugins, end its execution, or disconnect.

By December 2025, the malware had expanded to Linux while retaining MQTT for command and control. On Windows, BambooToken can deploy an antivirus plugin that uses Windows Management Instrumentation to identify installed antivirus products and exfiltrate those details to api80.c2iznja[.]com.

Lumen reported that the domains were proxied through Cloudflare. One domain tied to the 2025 campaign recently entered Cloudflare Radar's top 500,000 domains, while an older domain reached the top one million during peak operations in 2024. The researchers said these rankings indicate widespread infection across campaigns in the activity cluster.

Victims and defensive priorities

Researchers also identified IP addresses geolocated in Singapore, Cambodia and Vietnam communicating with an active command-and-control node; they corresponded to MikroTik and DrayTek routers. A dozen compromised entities were detected across Asia and South America, including organisations connected to mobile applications, a GitLab server in Hong Kong, a Vietnamese portable lifestyle-management-device developer, a Vietnamese hotel, a biomedical company in Argentina, a Chilean legal firm, a Lithuanian cryptocurrency website and a Malaysian financial organisation.

For businesses, the practical implication is to review DLL-sideloading exposure in deployed authentication software, investigate unexpected MQTT connections, and use endpoint telemetry to detect host reconnaissance and WMI queries aimed at security-product inventory.

#cybersecurity#malware#mqtt#endpointsecurity
Open analytics
On the site 0 views
min read 4 15.09.2026
Instagram

BambooToken campaign controls Windows and Linux systems over MQTT

Open the post on Instagram ↗