Hacking

BambooToken Malware Uses MQTT to Control Windows and Linux

Published  ·  7 min read

There's a malware family that's been flying under the radar since early 2023. It's called BambooToken. And it uses a messaging protocol you'd normally find in IoT devices to control infected machines.

Black Lotus Labs found it. They published their research recently. The campaign targets organizations in Asia and South America. Activity linked to it was still showing up as recently as July 2026.

Here's the thing. This isn't some script kiddie operation. The people behind it know what they're doing. They've stayed hidden for years.

Let me break it down.

Quick Summary

What

Details

Malware

BambooToken

Active since

February 2023

C2 protocol

MQTT

Targets

Asia and South America

Sideloading

Tendyron OnKey

Attribution

Possibly China-nexus

What Is BambooToken?

  • It's a multi-platform malware family. Windows and Linux. It uses MQTT Message Queueing Telemetry Transport as its command-and-control channel.
  • MQTT is a lightweight publish-subscribe protocol. It's designed for IoT devices. Low bandwidth. Efficient. And it turns out, pretty good for malware C2 too.
  • Black Lotus Labs found the malware on VirusTotal in early 2026. But the evidence shows it's been active since at least February 2023. Maybe longer.

The initial access vector? Still unknown. Researchers haven't figured out how it gets in.

The Tendyron OnKey Trick

Here's where it gets interesting. The attackers are using a legitimate security product to sideload their malware.

The product is Tendyron OnKey. It's a USB security token used for authentication. Banks use it. Government agencies use it. Tendyron claims 190 million tokens in circulation.

The attackers didn't compromise Tendyron's code-signing certificate. They didn't break into their build environment. Instead, they're using a version of the software that's vulnerable to DLL sideloading.

Here's how it works. The Tendyron OnKeySrv program loads a DLL called OnKeyToken_KEB.dll. If an attacker can replace that DLL with a malicious version, the legitimate program will load it. The malicious code runs. And because it's running inside a trusted, signed process, it's harder to detect.

"The actor used Tendyron's 'OnKey' software to sideload agents into targeted machines," Black Lotus Labs said in a report shared with The Hacker News.

The target needs to have the software installed. That's the catch. But if you're in a Chinese financial or government organization, there's a decent chance you do.

How the Malware Works

  • Early versions of BambooToken were pretty simple. They extracted the C2 server address from a .DAT file. If that file wasn't there, they fell back to a hard-coded server.
  • Once connected, they'd gather system details and send them to chat5188[.]tk. The server would send back commands. Load a plugin. Stop all plugins. Terminate. Disconnect.
  • Later versions got more sophisticated. They sideload that rogue DLL and enter a command loop. The C2 channel switches to MQTT.
  • By December 2025, BambooToken had expanded to Linux hosts. Same MQTT C2. Same approach.

"The first version of BambooToken was initiated via a PowerShell script," Ryan English, information security engineer at Lumen Technologies Black Lotus Labs, told The Hacker News.

 "The PowerShell script would act as a 'stager' by allocating memory and then running the malicious file. We assess that sideloading would likely trigger fewer EDR alerts, so as the campaign evolved so did that threat actors TTPs."

The MQTT Connection

MQTT for C2 isn't new. But it's not common either.

The most famous example is MQsTTang. That's a backdoor used by Mustang Panda, a Chinese nation-state group. It was spotted in January 2023. Same protocol. Different malware.

There are a few others:

Malware

What It Does

Tizi

Android malware, harvests data from messaging apps

WailingCrab

Loader distributed via shipping-themed emails

IOCONTROL

OT malware targeting IoT and SCADA systems

Both MQsTTang and BambooToken showed up around the same time. Early 2023. There's no evidence they're connected. But Lumen says it's possible the BambooToken actor borrowed a page from Mustang Panda's playbook.

"Using MQTT to control numerous clients from a central point, combined with routing via Cloudflare, enables large-scale operation through an unconventional communication method," Lumen said.

Who's Getting Hit?

A dozen compromised entities have been confirmed in Asia and South America. Here's the breakdown:

Target

Location

Mobile application servers

Various

GitLab server

Hong Kong

Portable lifestyle device company

Vietnam

Hotel

Vietnam

Biomedical company

Argentina

Legal firm

Chile

Cryptocurrency website

Lithuania

Finance organization

Malaysia

Most of the compromised servers are tied to mobile apps. That's a pattern. Mobile apps and smartwatches connected to cellular networks can reveal a lot about someone's life. Where they go. What they do. When they sleep.

The researchers also found IP addresses in Singapore, Cambodia, and Vietnam talking to one of the active C2 nodes. Those IPs belong to MikroTik and DrayTek routers.

"The domains used Cloudflare as a proxy for their infrastructure," Black Lotus Labs said. "One domain associated with the 2025 campaign recently entered the top 500,000 domains on Cloudflare Radar. The older domain ranked in the top 1 million at the peak of operations in 2024, indicating widespread infection across campaigns for this activity cluster."

Who's Behind It?

Nobody's named the actor yet. But there are clues.

DLL sideloading. A SoftEther VPN connection from a VPS to one of the C2 nodes. The targeting. All of it suggests a China nexus.

Most of the BambooToken samples on VirusTotal came from Chinese IP space. That's another data point.

But it's not definitive. Attribution is hard. Especially when the actor is this careful.

What You Should Do

1. Check for Tendyron OnKey.

If you have it installed, check the version. Look for the OnKeyToken_KEB.dll file. Modification is a problem in itself.

2. Watch out for any traffic that involves MQTT.

Default MQTT ports are 1883 and 8883. In case you have detected some traffic involving MQTT but you aren't using it for legitimate reasons, do further analysis.

3. Search for any connections with the C2 domains

  • chat5188[.]tk
  • api80.c2iznja[.]com

Block them. Check your logs for any connections.

4. Review PowerShell activity.

Early versions used a PowerShell stager. Look for scripts that allocate memory and run executables. That's suspicious.

5. Be wary of DLL sideloading.

Detect whether legitimate applications load DLLs from unusual places. Inspect the integrity of critical DLLs.

6. Think about what you're protecting.

If you're a mobile app developer, a financial institution, or a hospitality company, you might be a target. The attackers are looking for data. Transaction records. Travel history. Pattern-of-life information.

The Bottom Line

BambooToken is a multi-platform malware family that uses MQTT for C2. It's been active since 2023. It uses Tendyron OnKey to sideload its payload. It targets organizations in Asia and South America. And it's still active.

Quick Reference:

Key Point

Detail

Malware

BambooToken

Active since

February 2023

C2 protocol

MQTT

Sideloading

Tendyron OnKey

Targets

Asia, South America

C2 domains

chat5188[.]tk, api80.c2iznja[.]com

What to Do:

  • Check for Tendyron OnKey
  • Monitor for MQTT traffic
  • Block C2 domains
  • Review PowerShell activity
  • Watch for DLL sideloading
  • Protect your data

FAQ Section

What is BambooToken?

Malware family with multiple platforms, using MQTT as C&C communications protocol, and Windows and Linux as targets. Active since at least February 2023.

How does it get in?

The initial access vector is unknown. But the attackers use DLL sideloading through Tendyron OnKey to run their payload.

What is MQTT?

Message Queueing Telemetry Transport. A lightweight publish-subscribe protocol designed for IoT devices. It's being abused for malware C2.

Who is the target?

Asia-based and South American organizations. Mobile apps, financial institutions, hotels, and others.

From where did it originate?

Unknown. But taking into account the use of DLL sideloading, SoftEther VPN, and the Chinese IP addresses, it may somehow be connected with China.

What can I do?

Search for Tendyron OnKey. Check for MQTT traffic. Block C2 domains. Check for DLL sideloading.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067