BambooToken Malware Uses MQTT to Control Windows and Linux Systems
- ID
- 24767
- Status
- summarized
- Published
- 15 Sep 2026, 11:23 PM
- Fetched
- 16 Sep 2026, 1:46 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 16 Sep 2026, 1:47 AM
- Tags
- Audience
- developerssaas_founders
What happened
Lumen Black Lotus Labs disclosed BambooToken, a multi-platform malware family active since at least February 2023 that uses MQTT as a command-and-control channel to control Windows and Linux systems. The malware sideloads via Tendyron's OnKey PKI USB token software (190 million tokens in circulation, used in China's financial and government sectors), exploiting a DLL sideloading vulnerability. Targets span organizations across Asia and South America, with most VirusTotal uploads from Chinese IP space.
Why it matters
If you ship IoT or messaging systems using MQTT, this is a concrete example of attackers abusing the protocol's lightweight pub/sub model for stealthy C2—worth reviewing whether your MQTT brokers require authentication and TLS, since the protocol's permissive default configuration is exactly what makes it attractive. The DLL sideloading vector via a legitimate security token product also reinforces that signed binaries from trusted vendors are not inherently safe to allow unrestricted execution.
Discussion angle
How MQTT's lightweight, often under-secured pub/sub design makes it a growing C2 channel—and what minimum hardening (auth, ACLs, TLS) builders should apply if they use MQTT in production.