A previously unknown malware framework called BambooToken has been using the Message Queuing Telemetry Transport (MQTT) protocol to secretly control Windows and Linux systems, compromising servers used by mobile apps, legal and financial services, and software development. Researchers at ESET first documented an unrelated backdoor called MQsTTang in 2023, but it’s only now that we’re seeing the full extent of BambooToken’s capabilities.
BambooToken is particularly noteworthy because it uses MQTT to communicate with infected systems, making it harder for security teams to detect and block its activities. MQTT is a lightweight messaging protocol primarily designed for Internet of Things (IoT) devices, which relies on a central broker and channels called “topics” to relay messages from publishers to subscribers. This approach allows infected machines to subscribe to specific topics associated with their unique identifier, making it easier for attackers to send commands without directly connecting to the attacker’s infrastructure.
The researchers at Black Lotus Labs, Lumen’s research arm, have found that BambooToken infected systems by side-loading via a digitally signed Tendyron OnKey USB-token software or by impersonating the Kingsoft Office productivity suite. They also discovered that the malware publishes status and system information through the broker and receives operator instructions through subscribed topics, allowing for asynchronous communication and increased evasion and resilience.
One of the most concerning aspects of BambooToken is its ability to collect extensive system information from infected hosts, including details about antivirus products installed on those systems. The researchers found strings pointing to keylogging, clipboard theft, audio recording, webcam capturing, and screenshot capturing, although they couldn’t determine if these modules existed in attacks or were still under development.
Lumen’s telemetry has identified approximately a dozen compromised enterprise entities, mostly in Asia and South America, including hotels, biomedical firms, law firms, a financial organization, and a cryptocurrency website in Lithuania. The researchers also found that the most compromised servers were associated with the backend infrastructure of mobile applications, creating a potential foothold for supply-chain attacks.
Although the researchers couldn’t attribute BambooToken activity to a specific threat actor or a known activity cluster, they note that the targeting patterns are consistent with China-aligned operations. Lumen has shared indicators of compromise (IoCs) associated with this activity to help defenders detect and block the attacks.
The discovery of BambooToken highlights the ongoing threats posed by sophisticated malware frameworks using unconventional communication protocols like MQTT. As security teams work to stay ahead of these evolving threats, it’s essential to remain vigilant about potential vulnerabilities in software development kits (SDKs), digital certificates, and other components used in mobile app backend infrastructure. By sharing IoCs and collaborating with researchers, defenders can better detect and respond to these types of attacks, ultimately protecting users from the malicious activities of threat actors like those behind BambooToken.
Source: Bleeping Computer — 2026-09-15