Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.
The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America. Activity linked to the malware has been detected as recently as July 2026.
Lumen Black Lotus Labs said it discovered the previously undocumented malware on VirusTotal in early 2026, with evidence pointing to a skilled threat actor that has managed to stay undetected until now. The initial access vector used to deliver BambooToken remains undetermined.
"The actor used Tendyron's 'OnKey' software to sideload agents into targeted machines," Black Lotus Labs said in a report shared with The Hacker News. "Tendyron creates hardware-based tokens employed in high-security settings to verify user identities for workstation access. Their website lists customers in China's financial and government sectors, among other verticals"
Tendyron OnKey is a second-generation Public Key Infrastructure (PKI) USB security token and authentication device designed to protect online banking and financial transactions. On its website, Tendyron claims to have 190 million tokens in circulation.
Although neither Tendyron's code-signing certificate nor its build environment has been compromised in connection with the activity, it's suspected that the operators are relying on binary that's vulnerable to DLL sideloading to trigger the attack within targeted networks that are likely to have the program installed.
In addition, most of the BambooToken samples have been uploaded to the VirusTotal platform from the Chinese IP address space, indicating a data collection campaign targeting users within and other neighboring countries.
The use of MQTT, a lightweight, publish-subscribe network protocol, for remote command-and-control (C2) is not a new phenomenon. As far back as January 2023, the Chinese nation-state hacking group known as Mustang Panda was observed using a backdoor called MQsTTang that used the IoT messaging protocol to fetch and execute commands on compromised hosts.
Besides MQsTTang, there have been only a handful of campaigns that have used MQTT to date -
- An Android malware called Tizi that can harvest sensitive data from various messaging and social media apps, as well as use HTTPS or MQTT for C2 to realize its goals.
- A malware loader called WailingCrab (aka WikiLoader) that's distributed via delivery- and shipping-themed email messages. It's attributed to a cybercrime group called Bamboo Spider.
- An operational technology (OT) malware called IOCONTROL (aka OrpaCrab) that has targeted IoT and SCADA systems in Israel and the U.S.
Early iterations of the BambooToken agent work by extracting the C2 server from a .DAT file, or falling back to a hard-coded server if the file is not found. Once this step is complete, the malware proceeds to gather system details and transmit them to the C2 server ("chat5188[.]tk"). In response, the server issues commands to load a plugin, stop all plugins, terminate the execution of the malware, and disconnect from the C2 server.
Subsequent versions of the malware sideload a rogue version of a DLL ("OnKeyToken_KEB.dll") used by the Tendyron OnKeySrv program to enumerate the host and enter into a command loop that uses MQTT for C2. As of December 2025, BambooToken has expanded in scope to also target Linux hosts while still relying on MQTT.
"The first version of BambooToken was initiated via a PowerShell script," Ryan English, information security engineer at Lumen Technologies Black Lotus Labs, told The Hacker News. "The PowerShell script would act as a 'stager' by allocating memory and then running the malicious file. We assess that sideloading would likely trigger fewer EDR alerts, so as the campaign evolved so did that threat actors TTPs."
BambooToken is equipped to collect extensive host information and deliver an antivirus plugin for Windows that uses the Windows Management Instrumentation (WMI) framework to gather details about installed antivirus products on the machine and exfiltrate them to the C2 server ("api80.c2iznja[.]com").
"The domains used Cloudflare as a proxy for their infrastructure," Black Lotus Labs said. "One domain associated with the 2025 campaign recently entered the top 500,000 domains on Cloudflare Radar. The older domain ranked in the top 1 million at the peak of operations in 2024, indicating widespread infection across campaigns for this activity cluster."
The threat research arm of Lumen also said it identified IP addresses geolocated to Singapore, Cambodia, and Vietnam communicating with one of the active C2 nodes. These IP addresses correspond to MikroTik and DrayTek routers. In addition, a dozen compromised entities have been detected in Asia and South America.
The vast majority of the compromised servers are associated with mobile applications, as well as a GitLab server in Hong Kong and a Vietnamese company developing a portable lifestyle management device. Other targets include a hotel in Vietnam, a biomedical company in Argentina, a legal firm in Chile, a cryptocurrency website in Lithuania and a Malaysian finance organization.
It's unknown at this stage who is behind the activity. But the use of DLL sideloading, coupled with a SoftEther VPN connection originating from a Virtual Private Server (VPS) to one of the C2 nodes, suggests a China nexus.
Another interesting aspect worth mentioning is that both MQsTTang and BambooToken emerged around the same time in early 2023. While there is no evidence of any overlap between the two threat activity clusters, Lumen said it's possible the threat actor could have taken a leaf out of the Mustang Panda playbook to update its own malware to support MQTT in the upcoming versions.
"Using MQTT to control numerous clients from a central point, combined with routing via Cloudflare, enables large-scale operation through an unconventional communication method," Lumen concluded.
"We believe this campaign's targeting supports extensive data collection. Mobile apps and smartwatches connected to cellular networks could enable pattern-of-life analysis; targeting financial organizations might expose transaction data, and attacking hospitality systems could reveal travel history and plans."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.












English (US) ·