news.mlab.sh
Back to the feed
threat-intel

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

High
Summary

A multi-platform malware campaign, dubbed BambooToken, is leveraging the MQTT protocol to control Windows and Linux systems, originating from a Chinese threat actor. The malware, active since at least February 2023, utilizes DLL sideloading and a SoftEther VPN connection to maintain operational stealth and control a wide range of targets across Asia and South America, including mobile apps, financial organizations, and hospitality systems. The campaign is suspected of extensive data collection, potentially targeting patterns of life and financial transactions.

Cybersecurity researchers at Lumen Black Lotus Labs have uncovered a multi-platform malware campaign, BambooToken, utilizing the MQTT protocol for remote command-and-control. The campaign began in February 2023 and has been active through July 2026, targeting organizations in Asia and South America. The malware is associated with a Chinese threat actor, and evidence points to a connection with Tendyron, a company specializing in hardware-based security tokens.

BambooToken employs DLL sideloading and a SoftEther VPN connection to maintain operational stealth and control a wide range of targets. The malware extracts a C2 server from a .DAT file or falls back to a hard-coded server if the file is not found. Once connected, it gathers system details and delivers a Windows antivirus plugin using the Windows Management Instrumentation (WMI) framework to identify installed antivirus products and exfiltrate them to the C2 server ("api80.c2iznja[.]com").

Subsequent versions of the malware sideload a rogue DLL ("OnKeyToken_KEB.dll") used by the Tendyron OnKeySrv program to enumerate the host and enter a command loop that uses MQTT for C2. The malware is equipped to collect extensive host information and has expanded to target Linux hosts while still relying on MQTT.

Researchers identified IP addresses geolocated to Singapore, Cambodia, and Vietnam communicating with one of the active C2 nodes, and these IP addresses correspond to MikroTik and DrayTek routers. Dozens of compromised entities have been detected in Asia and South America, including a GitLab server in Hong Kong, a Vietnamese company developing a portable lifestyle management device, a hotel in Vietnam, a biomedical company in Argentina, a legal firm in Chile, a cryptocurrency website in Lithuania, and a Malaysian finance organization.

The campaign utilizes Cloudflare as a proxy for its infrastructure, with domains ranking in the top 500,000 on Cloudflare Radar at their peak in 2024. The use of MQTT to control numerous clients from a central point, combined with routing via Cloudflare, enables large-scale operation through an unconventional communication method. Researchers believe this campaign's targeting supports extensive data collection, potentially enabling pattern-of-life analysis and exposing sensitive financial data.

Read the full article at The Hacker News