Researchers at Lumen’s Black Lotus Labs have documented a previously unseen malware family that runs on both Windows and Linux and takes its orders over MQTT, the lightweight messaging protocol normally associated with IoT gear.
Dubbed BambooToken, the campaign is assessed to have been active since at least February 2023 and has hit organizations across Asia and South America, with activity seen as recently as July 2026. Analysts found it on VirusTotal in early 2026. Nobody has determined how it gets in.
The delivery trick depends on trust. Operators sideload a rogue DLL through OnKey, a PKI USB authentication token made by Tendyron that guards online banking sessions and is common in China’s financial and government sectors. Neither Tendyron’s code-signing certificate nor its build environment was compromised, so the implant rides a legitimate, signed binary that targeted networks are likely to already have.
Early versions pulled a command server from a .DAT file, falling back to a hardcoded address, then gathered host details. Later builds entered a command loop over MQTT. The first wave arrived through a PowerShell stager that allocated memory before running the payload; the shift to sideloading was likely an effort to cut EDR alerts.
The malware also ships an antivirus enumeration plugin that uses WMI to inventory security products on the host. Most samples came from Chinese IP space and logged into Cloudflare-fronted infrastructure.
Twelve organizations are known to be compromised, among them mobile app servers, a GitLab instance in Hong Kong, a Vietnamese hotel, a biomedical company in Argentina and a finance firm in Malaysia. MikroTik and DrayTek routers in Singapore, Cambodia and Vietnam were seen talking to live command nodes, pointing to a China nexus.
