BambooToken Malware Uses MQTT to Control Windows and Linux Systems
AI-summarised brief · reviewed before publication
Cybersecurity researchers uncovered BambooToken, a multi‑platform malware that has operated since February 2023, targeting Windows and Linux systems across Asia and South America. The campaign uses the MQTT protocol for command‑and‑control, a rare choice for malware. BambooToken is delivered via Tendyron’s OnKey USB security token, exploiting DLL sideloading to evade detection. The malware collects extensive system data, exfiltrates antivirus information, and has been observed communicating from Chinese IP addresses and Cloudflare‑proxied domains.
💡 Why It Matters
- · The use of MQTT for remote control demonstrates a shift toward lightweight, IoT‑centric C2 channels, complicating traditional security monitoring.
- · BambooToken’s exploitation of trusted hardware tokens underscores the vulnerability of even high‑security authentication devices to sophisticated supply‑chain attacks.