Threats · 5h ago
Lumen Black Lotus Labs says BambooToken has been active since at least February 2023 and has been tied to attacks on organizations in Asia and South America. The malware family targets both Windows and Linux and uses MQTT, the Message Queuing Telemetry Transport protocol, for command-and-control.
The delivery trick is the trusted helper software itself: Black Lotus Labs says the operators use Tendyron OnKey to sideload agents onto targeted machines. That means the signed token app starts, but loads the attacker’s code alongside its own, so the malware runs under the cover of software meant to verify workstation access.
For shops that depend on USB token utilities to gate logins, the exposed layer is the workstation software, not the token hardware. If that helper app is abused, a high-trust endpoint can be implanted and still phone home over MQTT even when the authentication model looks strong on paper.
2 sources covering this story
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
BambooToken uses MQTT for C2 across Windows and Linux, with a dozen compromised entities detected in Asia and South America.
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.
Part of the PlainSec briefing for 2026-09-15