The discovery of BambooToken provides an important example of how attackers are increasingly adapting legitimate communication protocols to make command-and-control traffic more resilient and difficult to distinguish from normal network activity. BambooToken is a previously undocumented malware framework that researchers believe has been active since at least 2023 and has evolved to target both Windows and Linux systems. More recent variants use the Message Queuing Telemetry Transport protocol, better known as MQTT, for command-and-control communications. MQTT was designed as a lightweight publish-and-subscribe messaging protocol for Internet of Things devices and other environments where efficient communication between systems is important, but BambooToken demonstrates that the same characteristics that make MQTT useful for legitimate machine-to-machine communication can also make it attractive to attackers seeking a flexible and less conventional communication channel.
BambooToken’s use of MQTT is particularly interesting because infected machines do not necessarily need to establish a direct connection with infrastructure clearly associated with the attacker. Instead, the malware subscribes to MQTT topics linked to a unique system identifier, while the operator publishes commands to those topics through a broker. Compromised machines can then publish system information and execution results back through the same messaging infrastructure. This decouples the attacker from the infected endpoint because the malware and operator communicate through an intermediary broker rather than maintaining a traditional direct command-and-control connection. From a defensive perspective, that architecture can make attribution and detection more difficult because blocking a single attacker-controlled server may no longer disrupt the operation in the way defenders expect from conventional malware.
The publish-and-subscribe nature of MQTT also provides operational resilience. Commands can be placed on defined topics and retrieved by malware when the infected system becomes available, allowing communications to function even when connectivity is intermittent. That asynchronous capability is useful in legitimate IoT deployments where sensors and devices may not always remain online, but malware operators can exploit the same design to maintain control over compromised hosts across unreliable network conditions. Security teams therefore need to recognise that protocols designed for reliability and scalability can provide those exact same benefits to malicious infrastructure when they are abused.
The malware’s infection methods are equally noteworthy because they demonstrate the continuing effectiveness of abusing trusted software rather than relying entirely on obviously malicious executables. Researchers found BambooToken being side-loaded through digitally signed Tendyron OnKey USB-token software and also observed versions masquerading as the Kingsoft Office productivity suite. DLL side-loading remains attractive because attackers can place a malicious library alongside a legitimate signed executable and rely on normal Windows loading behaviour to execute their code. To the user, and sometimes to basic security controls, the visible process may appear to belong to trusted software even though malicious code is executing inside or alongside it. This reinforces why application reputation and digital signatures should be treated as security signals rather than absolute guarantees of safe behaviour.
The use of USB-token related software is especially interesting in an enterprise context because authentication and cryptographic utilities are often granted a high degree of user trust. Employees are conditioned to install or interact with applications associated with digital signatures, certificates and authentication tokens, particularly in legal, financial and government environments. Attackers who abuse such software gain not only a technical execution mechanism but also a social advantage because users are less likely to question processes associated with software they believe exists specifically to improve security. This is another reminder that attackers frequently succeed by borrowing existing trust rather than trying to manufacture credibility from nothing.
Researchers also recovered functionality capable of enumerating antivirus products installed on compromised machines, which provides operators with useful information before they deploy additional capabilities. Understanding what security software is present allows attackers to modify behaviour, select alternative payloads or decide whether a particular target is worth further exploitation. Strings found within the malware also referenced capabilities including keylogging, clipboard theft, audio recording, webcam access and screenshot capture, although researchers appropriately noted that these references appeared in dead code and therefore could not confirm that every capability was actually implemented or used operationally. That distinction matters because threat reporting should separate demonstrated behaviour from functionality suggested by unfinished or inactive code rather than automatically attributing every developer string to real-world attacks.
The Linux variant of BambooToken makes the framework considerably more significant because it shows that the operators are not limiting themselves to ordinary Windows workstations. The most recent Linux sample observed by researchers could collect extensive information about a system, launch a command shell and allow operators to upload, download and delete files. Although researchers assessed that the Linux version still appeared to be under development, its existence suggests that BambooToken is evolving toward a genuinely cross-platform intrusion framework. This reflects a wider shift in enterprise attacks as adversaries increasingly target Linux servers, network appliances and cloud workloads rather than assuming that valuable infrastructure exists exclusively on Windows endpoints.
That shift becomes particularly important when looking at the systems BambooToken has reportedly compromised. Researchers identified roughly a dozen enterprise victims across Asia and South America, including organisations in hospitality, biomedical services, law, finance and cryptocurrency, while many of the affected systems were associated with mobile application backend infrastructure. Servers supporting mobile applications can be extremely valuable targets because a single compromised backend may interact with large numbers of users and contain API keys, credentials, application data and privileged connections to other services. An attacker who compromises the backend of an application may therefore gain substantially more strategic value than compromising one individual user endpoint.
The compromise of a GitLab server in Hong Kong is perhaps one of the most concerning findings because developer infrastructure creates the possibility of supply-chain escalation. A compromised source-code or DevOps platform can provide access to repositories, build processes, deployment credentials and software-development secrets, depending on the permissions available to the attacker. Even when researchers have not confirmed that software supply-chain manipulation actually occurred, gaining a foothold within development infrastructure creates opportunities that defenders should treat extremely seriously. Attackers increasingly understand that compromising the systems used to build or distribute software can provide access to far more downstream victims than attacking those victims individually.
The targeting profile also suggests that BambooToken may be oriented toward intelligence collection rather than purely opportunistic cybercrime. Researchers observed victims across sectors that can hold commercially or strategically valuable information and noted that some activity may have involved overseas Chinese users accessing mainland services through the SpeedCN VPN service. At the same time, the researchers were unable to attribute BambooToken conclusively to a known threat actor and described the activity only as consistent with China-aligned operations. This distinction is important because technical similarities, geography and victim selection can suggest an intelligence objective without being sufficient to make definitive attribution, and responsible threat intelligence should preserve that uncertainty.
For defenders, MQTT usage creates a useful monitoring lesson. Organisations often create security policy around protocols such as HTTP, HTTPS, DNS and SSH because those are well-understood channels for command and control, while less commonly used protocols can receive significantly less scrutiny. In environments where MQTT has no legitimate business purpose, outbound connections using the protocol should immediately attract attention. Where MQTT is legitimately deployed, monitoring needs to become more contextual, examining which systems are communicating with brokers, whether those destinations are expected and whether ordinary workstations or servers have suddenly begun generating publish-and-subscribe traffic inconsistent with their role.
Network security controls should therefore understand application behaviour rather than relying exclusively on ports. MQTT typically uses TCP port 1883 or 8883 for TLS-protected communication, but attackers are not obligated to respect conventional port assignments, and simple port blocking is therefore an incomplete control. Application-aware inspection, DNS monitoring, destination reputation and behavioural analytics can help identify communication patterns that deviate from expected use even when the underlying protocol itself is perfectly legitimate. This becomes increasingly important as attackers move toward common cloud services, messaging platforms and standard protocols precisely because defenders cannot simply block them without affecting legitimate business activity.
BambooToken also demonstrates why encrypted traffic creates a growing visibility challenge. MQTT can operate over TLS, meaning network devices may be able to observe the connection destination and traffic characteristics without seeing the actual commands exchanged inside the encrypted session. This does not make detection impossible, but it increases the importance of correlating network context with endpoint telemetry. A server unexpectedly establishing persistent MQTT connections to an external broker, followed by unusual shell execution or file activity, becomes much more suspicious when both network and host behaviour are analysed together than when either event is examined independently.
Organisations should also pay closer attention to software side-loading and unusual execution relationships. Endpoint detection platforms can identify legitimate signed applications loading DLLs from unexpected directories, processes launching from temporary or user-writable locations and trusted applications spawning command shells that would not normally be part of their behaviour. These behavioural relationships are often more useful than simply checking whether the parent executable has a valid digital signature because BambooToken demonstrates how trusted software can become the vehicle through which malicious components execute.
The cross-platform nature of the malware reinforces the need for consistent security visibility across Windows and Linux environments. Many enterprises have strong endpoint monitoring on employee Windows devices but weaker telemetry on application servers, developer infrastructure and Linux-based backend systems. Attackers naturally gravitate toward these gaps because persistence on a poorly monitored Linux server can remain unnoticed considerably longer than equivalent activity on a heavily monitored workstation. Security operations should therefore establish consistent baselines for process behaviour, network communications, privileged access and file changes across all important operating systems rather than allowing security coverage to depend on which platform happens to be easiest to instrument.
The broader lesson from BambooToken is that command-and-control detection can no longer depend simply on identifying obviously malicious protocols or connections to obviously malicious infrastructure. Attackers increasingly hide their operations inside legitimate technologies because those technologies provide reliability, encryption, scalability and a degree of implicit trust. MQTT is not malicious, just as cloud storage, DNS, HTTPS and remote-management tools are not malicious, but the context in which they are used determines whether that communication is legitimate or hostile. Security therefore needs to understand which protocols and services are expected for each asset and identify deviations from that expected behaviour.
BambooToken ultimately illustrates the growing importance of contextual security. A Windows workstation communicating through MQTT may be perfectly legitimate in an industrial environment and deeply suspicious inside a law firm. A signed USB-token application loading a particular library may be normal on one endpoint and evidence of side-loading on another. A Linux server opening an outbound messaging connection may be required application behaviour or an attacker waiting for commands. The technology itself does not provide the answer; identity, destination, application, asset role and behaviour together provide the context necessary to determine whether activity should be trusted. As attackers continue adopting legitimate protocols and software for malicious purposes, understanding that context will increasingly separate effective threat detection from security systems that simply recognise names and ports.
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
Source: BambooToken malware controls Windows and Linux systems via MQTT via Bleeping Computer — published 15 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.