BambooToken Malware Uses MQTT Protocol to Control Windows and Linux Systems and Evade Detection

Views: 32 views

514/69 Friday, September 18, 2026

Security researchers from Lumen have discovered a new malware family named BambooToken, which has been used to target Windows and Linux systems from February 2023 through July 2026. The malware hides its activity by using the MQTT protocol, a messaging protocol commonly used in smart home devices and industrial systems, as a channel for receiving and sending commands. Because communication occurs through an intermediary broker, infected machines do not need to connect directly to a command-and-control (C2) server, making anomalous activity harder to detect. Successful attacks could affect both small network devices and enterprise infrastructure, potentially leading to broader supply-chain security risks.

From a technical perspective, the Windows version of the malware uses sideloading techniques to hide within trusted software, such as Tendyron’s OnKey program and applications impersonating Kingsoft Office software, allowing it to run without immediately raising suspicion from security tools. It also checks for antivirus processes on the system every five seconds. The Linux version is capable of enabling remote control and uploading or downloading files. Based on enterprise attack campaign data from January to September 2026, the targets covered multiple sectors, including mobile application servers, software and technology organizations, legal and financial services, hotel businesses, and biomedical companies. Victims were observed across several countries, although no specific threat actor has been confirmed at this stage.

To prevent and reduce risk, administrators should thoroughly review the software supply chain and components used within their organizations. They should also apply security patches to routers, block unauthorized SNMP traffic, and change default passwords on network devices. Organizations should monitor outbound network traffic over MQTT, especially from devices or applications that have no business need to use the protocol. Endpoint detection and response (EDR) tools should also be configured to detect lateral movement within networks, rather than relying solely on detection based on known malware signatures.

Source: https://securityaffairs.com/199205/malware/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar.html