AI Weekly Malaysia

Back to items Summaries

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

ID
24767
Status
summarized
Published
15 Sep 2026, 11:23 PM
Fetched
16 Sep 2026, 1:46 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
16 Sep 2026, 1:47 AM
Tags
Audience
developerssaas_founders

What happened

Lumen Black Lotus Labs disclosed BambooToken, a multi-platform malware family active since at least February 2023 that uses MQTT as a command-and-control channel to control Windows and Linux systems. The malware sideloads via Tendyron's OnKey PKI USB token software (190 million tokens in circulation, used in China's financial and government sectors), exploiting a DLL sideloading vulnerability. Targets span organizations across Asia and South America, with most VirusTotal uploads from Chinese IP space.

Why it matters

If you ship IoT or messaging systems using MQTT, this is a concrete example of attackers abusing the protocol's lightweight pub/sub model for stealthy C2—worth reviewing whether your MQTT brokers require authentication and TLS, since the protocol's permissive default configuration is exactly what makes it attractive. The DLL sideloading vector via a legitimate security token product also reinforces that signed binaries from trusted vendors are not inherently safe to allow unrestricted execution.

Discussion angle

How MQTT's lightweight, often under-secured pub/sub design makes it a growing C2 channel—and what minimum hardening (auth, ACLs, TLS) builders should apply if they use MQTT in production.

Top