BambooToken Malware Controls Windows and Linux Systems via MQTT
Black Lotus Labs (Lumen) described BambooToken malware active since 2023. Since 2024-2025 it uses MQTT for command servers, infecting Windows and Linux via signed Tendyron OnKey software and a fake Kingsoft Office. About a dozen organizations in Asia and South America were affected.
- Malware uses MQTT broker and topics instead of direct C2 channels
- Infection via side-loading Tendyron OnKey and fake Kingsoft Office
- Linux variant BambooToken 2.1 spotted in December 2025
- Hotels, law firms, biomed and a Hong Kong GitLab server compromised
Read next
Security