// 2 ZERO-DAY · 5 CVE · 5 EXPLOIT · 1 ADVISORY IN THE LAST 24H
Black Lotus Labs has identified BambooToken, a malware framework active since 2023 that adopts the MQTT protocol for command and control of enterprise systems.

A September 2026 report has made public what was unknown until days earlier: a malware framework called BambooToken operated for at least three years undetected, compromising roughly a dozen enterprise entities in Asia and South America. According to Black Lotus Labs, the threat intelligence division of Lumen Technologies, the framework adopts the MQTT protocol — standard in the IoT ecosystem — for command-and-control communications, an approach the researchers describe as "uncommon." The latest variants, developed between 2024 and 2025, target Windows and Linux servers with side-loading techniques and data-collection capabilities still evolving.

Key Takeaways
  • BambooToken is a malware framework active since at least 2023, with MQTT variants developed between 2024 and 2025
  • The MQTT protocol is described as an "uncommon approach" for C2, offering evasion and resilience advantages
  • Infection occurs via DLL side-loading through digitally signed Tendyron OnKey USB-token software or by impersonating Kingsoft Office
  • The latest Linux variant, version 2.1 observed in December 2025, is assessed as still under development
  • Roughly a dozen compromised enterprise entities, primarily in Asia and South America; sectors: hospitality, biomedical, legal, finance, cryptocurrency

Context: MQTT in Malware, From Rarity to Pattern

The MQTT protocol is not new to the malware landscape. In 2023, ESET documented MQsTTang, a backdoor attributed to the Chinese group Mustang Panda, which exploited the same protocol for C2 communications. The difference with BambooToken lies in the target: while MQsTTang hit individual endpoints, BambooToken focuses on enterprise servers and backend infrastructure. According to Black Lotus Labs, this choice reflects a specific operational logic: legitimate MQTT brokers provide a layer of indirection that complicates identification of malicious infrastructure, and the protocol is designed for automatic reconnections that increase resilience.

The report does not explain why operators preferred MQTT over more traditional C2 techniques for the identified victims. However, the concentration of compromised servers associated with mobile app backends suggests a possible link: these infrastructures already handle data flows from mobile devices, where MQTT is widespread, and the protocol's presence might appear less anomalous to monitoring systems.

Infection Mechanisms: Windows and Linux Compared

On Windows, BambooToken establishes persistence via DLL side-loading. Researchers identified two specific vectors: Tendyron OnKey software, used for cryptographic USB tokens and digitally signed, and impersonation of Kingsoft Office, a productivity suite popular in Asian markets. The technique allows malicious code to load in processes bearing an apparently legitimate signature.

A plugin recovered from the Windows variant enumerates antivirus products installed on the host. Strings in non-executed code sections — "dead code" in Black Lotus Labs' terminology — reference keylogging, clipboard theft, audio recording, webcam capture, and screenshot functionality. Researchers cannot determine with certainty whether these modules existed in active samples or remain in an incomplete development state.

On Linux, the framework reaches version 2.1 in December 2025. This variant collects extensive system information, allows remote command shell spawning, and handles file upload, download, and deletion operations. Black Lotus Labs assesses that "the Linux sample still appeared to be under development" — an indication the framework continues to evolve on both platforms.

"the Linux sample still appeared to be under development" — Black Lotus Labs (via BleepingComputer)

Victims, Sectors, and the Lithuanian Anomaly

Black Lotus Labs identified roughly a dozen compromised enterprise entities, distributed primarily in Asia and South America. Targeted sectors include hospitality, biomedical, legal, finance, and cryptocurrency. A specific case in Lithuania — the only one in Europe — breaks the dominant geographic concentration. The report does not explain this anomaly: it could reflect a victim with branches in other regions, cloud infrastructure with a legal domicile different from its physical location, or a test of geographic expansion by the operators.

A recurring pattern emerges in the type of servers most frequently compromised: mobile application backend infrastructure. This concentration is not analyzed in the report as a deliberate attacker choice, but constitutes an observational data point that raises questions about a possible link between MQTT usage and the mobile ecosystem.

Of particular note is the compromise of a GitLab server in Hong Kong. According to Black Lotus Labs, this creates a "potential foothold for supply-chain attack" — a possibility the report does not develop beyond the generic indication.

Attribution: Hypotheses and Limits

Lumen advances a hypothesis of specific targeting: Chinese users abroad who use SpeedCN VPN. The victim selection pattern is described as "consistent with China-aligned operations," but researchers do not attribute the activity to a known threat actor or documented activity cluster. Operator identity remains unconfirmed, and the report provides no technical elements — such as source code, infrastructure, or TTPs — that would link BambooToken to previously attributed campaigns.

This caution is significant: geographic and sectoral consistency alone with operations attributed to Chinese groups does not constitute proof of attribution. The report presents it as a contextual indicator, not a conclusion.

What This Changes

DeafNews analysis: the revelation of BambooToken raises three strategic questions for enterprise security teams. First: monitoring MQTT traffic in environments where the protocol is not expected — backend servers, workstations, non-IoT infrastructure — warrants specific attention, given that at least one documented malware framework uses it as a primary C2 channel. Second: side-loading via digitally signed software like Tendyron OnKey shows that a signature is no guarantee of safety, and controls must verify not only who signed but what gets loaded. Third: the presence of "dead code" with advanced capabilities in a framework active since 2023 suggests operators are preparing future expansions, or that inactive code serves to test capabilities without exposure — or that it consists of development artifacts without operational significance. The source does not specify which interpretation is correct.

The Hong Kong GitLab server compromise, finally, indicates the target is not only direct exfiltration but potentially the compromise of software development supply chains — even though the report does not document that this potential was actually realized.

Methodology Note

This article is based on the Black Lotus Labs (Lumen Technologies) report as reported by BleepingComputer. Direct primary sources to the original report are not available. Quotes attributed to Black Lotus Labs are relayed through BleepingComputer. Interpretive analyses are signed DeafNews and are not present in the researchers' report.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. research.checkpoint.com
  3. rapid7.com
  4. ics-cert.kaspersky.com
  5. deals.bleepingcomputer.com