BambooToken malware controls Windows and Linux systems via MQTT command-and-control
Lumen Black Lotus Labs exposes BambooToken, a China-aligned malware framework active since February 2023 that uses MQTT for C2 to backdoor roughly a dozen Windows and Linux hosts across Asia and South America.
Lumen's Black Lotus Labs disclosed BambooToken, a previously undocumented multi-platform malware framework active since at least February 2023, which adopted the MQTT publish-subscribe protocol for command-and-control in 2024-2025 variants targeting both Windows and Linux, with Linux variant 2.1 observed in December 2025 supporting file transfer and a command shell. Initial infection occurs via DLL side-loading of a rogue OnKeyToken_KEB.dll through digitally signed Tendyron OnKey PKI USB-token software or an impersonated Kingsoft Office installer. The malware gathers host details, uses a WMI-based plugin to enumerate installed antivirus products and exfiltrate the details to C2 domains proxied through Cloudflare, and contains dead code suggesting keylogging, clipboard theft, audio/webcam capture, and screenshot modules. Telemetry identified roughly a dozen compromised entities across Asia and South America — spanning finance, hospitality, biomedical, and legal sectors, including hotels, law firms, and a Hong Kong GitLab server, as well as possibly users of the SpeedCN VPN service. Both DLL sideloading tradecraft and SoftEther VPN usage, along with targeting patterns, suggest a China nexus, though no attribution to a known cluster was made.
- BambooToken active since at least February 2023; previously undocumented
- MQTT publish-subscribe protocol used for command-and-control, adopted in 2024-2025 variants
- Linux variant 2.1 observed December 2025, supporting file transfer and command shell
- Infection via DLL side-loading of rogue OnKeyToken_KEB.dll through digitally signed Tendyron OnKey software or fake Kingsoft Office installer
- WMI-based plugin enumerates installed antivirus products and exfiltrates details to Cloudflare-proxied C2 domains
- Dead code suggests keylogging, clipboard theft, audio/webcam capture, and screenshot modules
- Roughly a dozen victims across Asia and South America in finance, hospitality, biomedical, and legal sectors, including a Hong Kong GitLab server and possibly SpeedCN VPN users
- No attribution to a known cluster, but targeting patterns and tradecraft (DLL sideloading, SoftEther VPN) suggest a China-aligned actor
Coverage timelineoldest first · each row is one article
- · 7h agoBambooToken malware controls Windows and Linux systems via MQTT
BleepingComputer· 50
Lumen Black Lotus Labs exposes BambooToken, a China-aligned malware framework using MQTT C2 to backdoor Windows and Linux systems at roughly a dozen enterprises.
- · 6h agoBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News· 48
Lumen uncovers BambooToken, a stealthy multi-platform malware using MQTT C2 and Tendyron DLL sideloading to compromise Asian and South American organizations.