ZeroHour

Source: Security Affairs

2 stories in the last 7d

BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Lumen's Black Lotus Labs uncovered BambooToken, a Windows and Linux malware family using MQTT broker-based C2 and DLL sideloading across Asia since February 2023.

Lumen Black Lotus Labs identified BambooToken, a multiplatform malware family that exchanges commands through MQTT brokers so infected hosts never contact the C2 server directly, active from at least February 2023 through July 2026. The Windows variant sideloads via Tendyron's OnKey hardware-token software used in Chinese banking and government, or impersonates Kingsoft Office, without either vendor's signing certificate being compromised; a Linux build appeared by December 2025 with shell, file transfer, and system information commands. Victims include MikroTik and DrayTek routers in Singapore, Cambodia, and Vietnam reached after internet-wide SNMP scanning, and Lumen cannot attribute the family to any known actor.

Security Affairs · 2h agoMalware in the wild

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Security Affairs publishes Malware Newsletter Round 114, a routine weekly digest; page text only contains the site's cookie consent notice.

Security Affairs released Malware Newsletter Round 114, its recurring roundup of malware-related news, on September 13, 2026. The extracted article text contains only the website's cookie consent banner, so the specific malware stories covered in this edition are unknown. This is a routine digest item with no standalone incident details.

Security Affairs · 3d agoMalware1