ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

BambooToken malware controls Windows and Linux systems via MQTT command-and-control

mediumMalwareexploited in the wildimportance 50
What's new: Initial merged summary: combined BleepingComputer and The Hacker News reports on the BambooToken disclosure by Lumen Black Lotus Labs. No prior summary existed; reports were consistent, with The Hacker News providing more specific timing (February 2023 start date, rogue DLL name, Cloudflare-proxied C2) and BleepingComputer adding SpeedCN VPN association and dormant module capabilities.
Merged summary · glm-5.3 · rewritten as coverage arrives

Lumen Black Lotus Labs exposes BambooToken, a China-aligned malware framework active since February 2023 that uses MQTT for C2 to backdoor roughly a dozen Windows and Linux hosts across Asia and South America.

Lumen's Black Lotus Labs disclosed BambooToken, a previously undocumented multi-platform malware framework active since at least February 2023, which adopted the MQTT publish-subscribe protocol for command-and-control in 2024-2025 variants targeting both Windows and Linux, with Linux variant 2.1 observed in December 2025 supporting file transfer and a command shell. Initial infection occurs via DLL side-loading of a rogue OnKeyToken_KEB.dll through digitally signed Tendyron OnKey PKI USB-token software or an impersonated Kingsoft Office installer. The malware gathers host details, uses a WMI-based plugin to enumerate installed antivirus products and exfiltrate the details to C2 domains proxied through Cloudflare, and contains dead code suggesting keylogging, clipboard theft, audio/webcam capture, and screenshot modules. Telemetry identified roughly a dozen compromised entities across Asia and South America — spanning finance, hospitality, biomedical, and legal sectors, including hotels, law firms, and a Hong Kong GitLab server, as well as possibly users of the SpeedCN VPN service. Both DLL sideloading tradecraft and SoftEther VPN usage, along with targeting patterns, suggest a China nexus, though no attribution to a known cluster was made.

  • BambooToken active since at least February 2023; previously undocumented
  • MQTT publish-subscribe protocol used for command-and-control, adopted in 2024-2025 variants
  • Linux variant 2.1 observed December 2025, supporting file transfer and command shell
  • Infection via DLL side-loading of rogue OnKeyToken_KEB.dll through digitally signed Tendyron OnKey software or fake Kingsoft Office installer
  • WMI-based plugin enumerates installed antivirus products and exfiltrates details to Cloudflare-proxied C2 domains
  • Dead code suggests keylogging, clipboard theft, audio/webcam capture, and screenshot modules
  • Roughly a dozen victims across Asia and South America in finance, hospitality, biomedical, and legal sectors, including a Hong Kong GitLab server and possibly SpeedCN VPN users
  • No attribution to a known cluster, but targeting patterns and tradecraft (DLL sideloading, SoftEther VPN) suggest a China-aligned actor

Coverage timeline

  1. · 7h ago
    BleepingComputer· 50
    BambooToken malware controls Windows and Linux systems via MQTT

    Lumen Black Lotus Labs exposes BambooToken, a China-aligned malware framework using MQTT C2 to backdoor Windows and Linux systems at roughly a dozen enterprises.

  2. · 6h ago
    The Hacker News· 48
    BambooToken Malware Uses MQTT to Control Windows and Linux Systems

    Lumen uncovers BambooToken, a stealthy multi-platform malware using MQTT C2 and Tendyron DLL sideloading to compromise Asian and South American organizations.