BambooToken Malware Uses MQTT Protocol to Control Windows and Linux Systems, Compromising Enterprise Entities Worldwide
A sophisticated malware framework called BambooToken has been discovered using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with compromised Windows and Linux systems. The malware, which has been active since at least 2023, has been linked to a dozen enterprise entities across Asia and South America, including hotels, law firms, financial organizations, and cryptocurrency websites.
BambooToken’s use of MQTT is an uncommon approach, but one that provides the attackers with increased evasion and resilience. Infected systems do not connect directly to the attacker’s infrastructure, instead relying on a central broker to relay messages between publishers and subscribers. This allows the malware to remain hidden even in the event of temporary network disruptions.
The researchers at Black Lotus Labs, part of Lumen’s research arm, discovered that BambooToken infects systems by side-loading via digitally signed software or by impersonating legitimate productivity suites. The malware publishes status and system information through the broker and receives operator instructions through subscribed topics. This approach has been linked to a recent campaign targeting overseas Chinese users accessing mainland services through the SpeedCN VPN service.
The researchers found that the Linux variant of BambooToken, version 2.1, is still under development, but it already collects extensive system information, can spawn a command shell, and allows operators to upload, download, and delete files. The malware also enumerates antivirus products on infected hosts and returns the results to its C2 server.
A potential foothold for supply-chain attacks was discovered when Lumen’s researchers found that the threat actor compromised a GitLab server in Hong Kong. This server could be used as a launchpad for future attacks, further compromising the security of enterprise entities worldwide.
The targeting patterns of BambooToken activity are consistent with China-aligned operations, but no specific threat actor or cluster has been attributed to the campaign. Lumen has shared indicators of compromise (IoCs) associated with this activity to help defenders detect and block the attacks.
As cybersecurity threats continue to evolve, it is essential for organizations to stay vigilant and adapt their defenses accordingly. The discovery of BambooToken highlights the importance of monitoring MQTT protocol communications, as well as maintaining robust security measures, such as regular software updates and antivirus protection. By staying informed about emerging threats like BambooToken, organizations can better protect themselves against the evolving landscape of cyber attacks.
In light of this development, it is crucial for enterprise entities to review their security posture and take necessary precautions to prevent similar malware campaigns from succeeding in the future. This includes regularly updating software, implementing robust antivirus protection, and monitoring MQTT protocol communications for any suspicious activity.
Source: Bleeping Computer — 2026-09-15