Cyber Resilience
← All news
Corroborated

BambooToken malware controls Windows and Linux systems via MQTT

Our takeBambooToken, active since 2023, uses MQTT to control Windows and Linux systems while hiding its C2. The Black Lotus Labs report is corroborated; defenders should watch for unusual MQTT traffic on both platforms.
Sources (3)
What this means for you — Security leader:BambooToken is a modular malware framework active since 2023 that uses the MQTT IoT protocol for C2 on both Windows and Linux, allowing indirect control without direct attacker IP exposure. Review endpoint logs for unusual MQTT traffic on ports 1883/8883 and ensure EDR/XDR coverage includes behavioral detection for cross-platform persistence and command execution.
What this means for you — Lean IT orgs:If you run Windows or Linux servers or workstations, watch for unusual network traffic on MQTT ports (1883 or 8883) and keep your antivirus and operating systems updated. Most smaller teams have no direct action unless you see signs of compromise.
What this means for you — MSP:BambooToken targets both Windows and Linux endpoints using MQTT for stealthy command-and-control. Scan client environments for anomalous MQTT traffic, unknown scheduled tasks, or suspicious binaries; prioritize patching and EDR deployment on internet-facing or high-privilege systems across your managed base.
What this means for you — Researcher:BambooToken adopts MQTT for C2 to blend with IoT traffic and reduce direct infrastructure exposure. Track indicators for its Windows and Linux implementations, especially persistence mechanisms and module loading patterns.