BambooToken Controls Windows And Linux systems By Hiding Behind MQTT brokers

BambooToken routes C2 traffic through IoT message brokers, keeping its infrastructure hidden and infected machines from ever contacting the attacker directly.

Published on Sep 16, 2026
BambooToken Hides Its C2 Behind MQTT Brokers

BambooToken has been routing its command traffic through an MQTT (Message Queuing Telemetry Transport) broker, so infected machines never talk directly to the attacker’s servers, according to research published Sept. 15 by Black Lotus Labs.

Lumen’s threat research team could not attribute it to any known threat cluster and is tracking it as an emerging threat.

The framework dates to February 2023 but switched to MQTT, a publish-and-subscribe protocol built for Internet of Things devices, in a 2024 rebuild. Earlier versions used plain HTTP.

The broker sits between victim and operator. Black Lotus Labs said that buys three things: the rest of the infrastructure stays hidden, communication becomes asynchronous, and a bot has to be approved before it receives anything.

The team called the technique rare, rather than novel, finding only three prior cases in IOCONTROL, Korplug, and WailingCrab. Korplug has been tied to a suspected PRC-aligned actor, but Black Lotus Labs found no further technical overlap.

Sideloaded Through a Cryptographic Token

The Windows agent was sideloaded through Tendyron’s OnKey software, which reads cryptographic material from USB tokens and is widely deployed in Chinese banking and government networks.

Black Lotus Labs was explicit that neither Tendyron’s code-signing certificate nor its build environment was compromised, and that the signed executable was simply vulnerable to sideloading.

Unremoved code exposed more. Compilation flags that strip unused functions were left unset, leaving strings indicating keylogging, clipboard access, audio recording, and webcam capture capabilities.

Only one plugin has been recovered. It reports the antivirus products running on the host every five seconds, which Black Lotus Labs suspects made it the first thing deployed, so operators could avoid sending the rest of the toolkit to a machine that looked like a researcher’s.

Who Was Hit and How Widely

Lumen counted around a dozen compromised enterprises, mostly in Asia with two in South America. They included a GitLab server in Hong Kong, a Vietnamese hotel, a biomedical firm in Argentina, and a Chilean law practice, among others.

Separately, the malware’s SNMP port scanning drew sustained connections from over 150 routers. A few went on to hold persistent MQTT sessions with the C2, from Singapore, Cambodia, and Vietnam.

Two C2 domains reached Cloudflare Radar’s top 500,000 and top million, which Black Lotus Labs said indicates widespread infection and an actor experienced at running wide-reaching campaigns.

The company told organizations to map their supply chains and code dependencies, to patch routers, replace default SNMP community strings and passwords, and disable external SNMP access.

It also recommended firewall rules that flag abnormal protocols such as outbound MQTT traffic leaving the network, and monitoring for large outbound transfers even where the destination sits in the same region.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alessandro Mascellino
Alessandro Mascellino Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.