Cybersecurity researchers have uncovered a sophisticated, multi-platform threat campaign that leverages the lightweight Message Queueing Telemetry Transport (MQTT) protocol as an unconventional command-and-control (C2) communication channel. Operating across both Windows and Linux environments, the emerging malware family has been codenamed BambooToken. Threat intelligence analysts assess that this campaign has been active since at least February 2023, with newly discovered malicious activity and infrastructure detected as recently as July 2026. The campaign came to light when threat researchers at Lumen Black Lotus Labs identified the previously undocumented malware samples on VirusTotal in early 2026. The findings point to the hand of a skilled and methodical threat actor who has successfully maintained operational secrecy for years. According to technical reports shared with industry publications, the operators behind BambooToken orchestrated a targeted approach, deploying their tools against organizations spread primarily across Asia and South America. The Mechanism of Infiltration: Exploiting Trusted Workstation Software A central element of the BambooToken campaign involves the abuse of legitimate software components to establish a foothold within targeted networks. The threat actors were observed utilizing Tendyron’s "OnKey" software to sideload malicious agents directly onto targeted machines. Tendyron is a recognized developer of hardware-based Public Key Infrastructure (PKI) USB security tokens and secondary authentication devices designed to safeguard online banking, high-security workstation access, and sensitive financial transactions. With public claims of having roughly 190 million tokens in circulation globally, Tendyron’s technology is frequently deployed within high-security environments, including financial institutions and government sectors, particularly in regions such as China. Security investigators emphasize that neither Tendyron’s official code-signing certificates nor its internal build environments have been compromised in connection with these operations. Instead, the threat actors rely on deploying legitimate binaries known to be vulnerable to DLL sideloading. Within target environments where the Tendyron program is already installed or anticipated to be present, this technique tricks the operating system into executing rogue code alongside or instead of legitimate security libraries, thereby executing the attack payload without raising immediate suspicion from traditional security controls. Corroborating this operational footprint, the vast majority of BambooToken samples analyzed by researchers were initially uploaded to public threat-sharing platforms like VirusTotal from Chinese IP address spaces. This geographical concentration strongly indicates a focused data collection campaign directed at users within China and surrounding neighboring countries, before expanding its geographic reach. Evolution of the Threat: From Early Windows Iterations to Cross-Platform Expansion The use of the MQTT protocol—typically reserved for Internet of Things (IoT) devices and low-bandwidth machine-to-machine communication due to its lightweight publish-subscribe model—remains a rare tactic in advanced persistent threat toolkits. While nation-state groups such as the Chinese hacking collective Mustang Panda previously deployed an IoT-based backdoor called MQsTTang to fetch and execute commands over MQTT, very few threat actors have successfully operationalized this protocol for large-scale enterprise espionage. Early iterations of BambooToken operated through a straightforward parsing mechanism. The malware agent extracted its designated C2 server address from an accompanying configuration file with a .DAT extension, falling back to a hard-coded server address if the file could not be located. Once connectivity was established, the malware performed initial system reconnaissance, gathering detailed host information and exfiltrating the data to its initial C2 infrastructure, identified by researchers as chat5188[.]tk. In return, the server dispatched management directives instructing the agent to load specific operational plugins, halt running modules, disconnect, or terminate execution entirely. As the campaign matured, the operators refined their tradecraft. Subsequent versions of BambooToken transitioned to DLL sideloading, utilizing a rogue library named "OnKeyToken_KEB.dll" within the Tendyron OnKeySrv directory structure. This modification allowed the malware to continuously enumerate host systems while maintaining a persistent, resilient command loop anchored in the MQTT protocol. Furthermore, by December 2025, the scope of BambooToken expanded significantly to encompass Linux operating systems, demonstrating the developers’ intent to target multi-platform enterprise infrastructures while retaining their core C2 architecture. Throughout its operational lifecycle, BambooToken has proven capable of deep reconnaissance. Newer variants feature specialized plugins designed for Windows environments that leverage the Windows Management Instrumentation (WMI) framework. This capability enables the malware to systematically identify all installed antivirus and endpoint protection solutions on a compromised machine, pack the gathered intelligence, and exfiltrate it to newer C2 domains, such as api80.c2iznja[.]com. Infrastructure Resilience and Global Impact To obscure their operational footprint and maintain persistent access, the actors behind BambooToken made extensive use of commercial proxy services. Lumen Black Lotus Labs noted that the domains utilized in the campaign relied heavily on Cloudflare infrastructure to act as a reverse proxy, masking the true origin of the C2 nodes. Metrics gathered from web intelligence services underline the scale of the infections. One domain tied to the 2025 campaign managed to climb into the top 500,000 domains ranked by Cloudflare Radar, while an older domain peaked within the top one million during its heaviest operational phases in 2024. This trajectory highlights a broad and sustained campaign impacting multiple independent victim networks over an extended period. In addition to direct endpoint telemetry, researchers identified suspicious communications originating from IP addresses geolocated in Singapore, Cambodia, and Vietnam. These intermediary nodes frequently traced back to widely deployed networking hardware, specifically MikroTik and DrayTek routers, suggesting that the actors actively leveraged compromised edge devices to bounce traffic and obscure their true geographic origin. Victim telemetry uncovered by cybersecurity analysts reveals a diverse array of compromised entities spanning multiple critical industries. The majority of impacted servers are tied to mobile application development environments, alongside high-profile targets such as a GitLab server in Hong Kong, a Vietnamese enterprise specializing in portable lifestyle management devices, a local Vietnamese hotel, a biomedical research company based in Argentina, a legal practice in Chile, a cryptocurrency-focused web portal in Lithuania, and a prominent financial organization in Malaysia. While definitive attribution remains officially unconfirmed, analysts point to several technical indicators pointing toward a China-aligned nexus. These include the primary concentration of initial sample submissions, the strategic targeting of regional sectors, and the observation of SoftEther VPN connections routing traffic from Virtual Private Servers directly into the designated C2 nodes. Security experts conclude that the integration of MQTT for centralized command over disparate clients, paired with the obfuscation provided by Cloudflare proxy networks, represents an efficient blueprint for large-scale, clandestine data collection. By targeting mobile application servers, smart devices, financial institutions, and hospitality systems, the operators behind BambooToken appear uniquely positioned to harvest deep operational intelligence, ranging from pattern-of-life analysis and sensitive transaction histories to personal travel patterns and corporate records. Post navigation Why Isolated Security Testing Fails: The Rise of Autonomous Attack Chaining in Enterprise Defense Cybersecurity Researchers Warn of Mass-Scanning Campaign Targeting Exposed Vite Development Servers to Harvest Cloud Credentials