Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » BambooToken MQTT Malware Linked to Espionage Campaign Spanning Three Years
    Technology

    BambooToken MQTT Malware Linked to Espionage Campaign Spanning Three Years

    Gary BehanBy Gary Behan23/09/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    BambooToken MQTT malware
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    A previously unknown malware framework, BambooToken MQTT malware, has been quietly compromising Windows and Linux systems since at least February 2023, with activity now confirmed as recently as July 2026, according to Ampus Cyber. Lumen’s research arm, Black Lotus Labs, published its own analysis of the campaign, detailing how the malware uses the Message Queuing Telemetry Transport (MQTT) protocol for command-and-control (C2) communications, a trick that helps it dodge detection by avoiding any direct connection between infected machines and attacker infrastructure.

    MQTT is a lightweight messaging protocol built for Internet of Things (IoT) devices. It routes messages through a central broker via named channels called ‘topics’, rather than relying on direct peer-to-peer connections. A subscriber listens on a topic; a publisher pushes messages to it. For malware operators, that architecture is rather convenient: the infected host subscribes to topics tied to a unique identifier, the attacker publishes commands to those topics, and the compromised machine returns status and system data through the same broker. Nobody is talking directly to anyone, which makes traffic patterns harder to flag.

    Why BambooToken MQTT Malware Is Uncommon

    MQTT’s use in malware is genuinely rare. Ampus Cyber notes that only three prior campaigns are known to have adopted the protocol for malicious purposes. The cybersecurity company ESET documented one of those earlier cases in 2023, a backdoor called MQsTTang, though that campaign was unrelated to BambooToken. The asynchronous nature of MQTT also helps the malware maintain operational continuity during temporary network outages, since the broker queues messages until the subscriber reconnects.

    BambooToken variants using MQTT were developed between 2024 and 2025. Earlier activity, dating back to at least February 2023, also forms part of the campaign’s timeline. Infection routes documented by Black Lotus Labs include side-loading via a digitally signed Tendyron OnKey USB-token software and impersonating the Kingsoft Office productivity suite, two vectors that lend the malware a patina of legitimacy during initial execution.

    What BambooToken Can Do, and What Remains Uncertain

    Researchers recovered a BambooToken plugin capable of enumerating antivirus products on a compromised host and returning the results to the C2. Beyond that, strings found in the malware point to keylogging, clipboard theft, audio recording, webcam capture, and screenshot capture. The important caveat: these strings came from what Black Lotus Labs describes as ‘dead code’, so the researchers cannot say with confidence whether the referenced modules were ever deployed in live attacks or remained under development at the time they were found.

    The most recent variant identified is BambooToken version 2.1, a Linux build observed in December 2025. It communicates over MQTT, collects extensive system information, can spawn a command shell, and allows operators to upload, download, and delete files. Black Lotus Labs notes that ‘the Linux sample still appeared to be under development’, so the Linux side of this campaign may not yet be fully operational.

    Lumen’s telemetry identified approximately a dozen compromised enterprise entities, concentrated in Asia and South America. The list includes hotels, biomedical firms, law firms, a financial organisation, and a cryptocurrency website in Lithuania. The most heavily compromised servers were associated with the backend infrastructure of mobile applications, which speaks to the campaign’s focus on persistent, quiet access rather than opportunistic smash-and-grab.

    The threat actor also compromised a GitLab server in Hong Kong, a foothold that raises the spectre of supply-chain interference, given how many development pipelines run through GitLab infrastructure.

    Lumen hypothesises that some activity may have targeted overseas Chinese users accessing mainland services through the SpeedCN VPN service. The researchers stopped short of attributing BambooToken to a specific threat actor or known cluster, but they do note that the targeting patterns are consistent with China-aligned operations. Lumen has shared indicators of compromise (IoCs) with the security community to support detection and blocking efforts.

    With the campaign’s confirmed timeline now stretching from February 2023 to July 2026, and a Linux variant apparently still in active development, BambooToken does not look like a project winding down.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleBlack Axe cybercrime extradition brings five alleged leaders to US court
    Next Article CenterPoint Energy Data Breach Laid Bare by Unprotected Public API
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    Ransomware Attack Recovery Cost: Why the Ransom Is the Smallest Line on the Bill

    24/09/2026

    Copilot Buttons Missing in Outlook Traced to MAPI Profile Bug

    24/09/2026

    Windows Server 2022 End of Support Arrives in October, Time to Plan Your Upgrade

    24/09/2026

    Acronis cPanel backup plugin flaw added to CISA’s exploit catalogue

    23/09/2026

    CenterPoint Energy Data Breach Laid Bare by Unprotected Public API

    23/09/2026

    Black Axe cybercrime extradition brings five alleged leaders to US court

    22/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.