BambooToken Malware Controls Windows and Linux Systems via MQTT
Black Lotus Labs (Lumen) described BambooToken malware active since 2023. Since 2024-2025 it uses MQTT for command servers, infecting Windows and Linux via signed Tendyron OnKey software and a fake Kingsoft Office. About a dozen organizations in Asia and South America were affected.