Researchers have detailed a multi-platform malware family, dubbed BambooToken, that uses the Message Queuing Telemetry Transport (MQTT) protocol to communicate with compromised Windows and Linux systems. The framework is assessed to have been active since at least February 2023, with variants adopting MQTT for command-and-control between 2024 and 2025.

MQTT is a lightweight messaging protocol built for IoT devices. It relies on a central broker and message channels called “topics” rather than direct connections between attacker and victim. In BambooToken’s implementation, infected machines subscribe to topics tied to a unique identifier, publish status and system data through the broker, and receive operator commands via those same subscribed topics. Because infected hosts never connect directly to attacker infrastructure, the approach improves evasion and lets operations continue asynchronously through temporary network disruptions.

According to a report from Lumen’s Black Lotus Labs research arm, BambooToken has infected systems through side-loading via a digitally signed Tendyron OnKey USB-token application, as well as by impersonating the Kingsoft Office productivity suite. Researchers recovered a plugin that enumerates installed antivirus products and reports the results back to the command-and-control server. Strings referencing keylogging, clipboard theft, audio recording, webcam capture, and screenshot capture were also found, though these were located in dead code, meaning it is unclear whether those modules were ever deployed or remain under development.

A Linux variant, BambooToken version 2.1, was observed as recently as December 2025. It also communicates via MQTT, gathers extensive system information, can spawn a command shell, and lets operators upload, download, and delete files. Black Lotus Labs assesses this Linux sample still appears to be under active development.

Targeting and Scope

Lumen’s telemetry identified roughly a dozen compromised enterprise entities, concentrated in Asia and South America, including hotels, biomedical firms, law firms, a financial organization, and a cryptocurrency website in Lithuania. The most heavily targeted servers were tied to backend infrastructure supporting mobile applications. Researchers also found that a GitLab server in Hong Kong had been compromised, creating a potential foothold for supply-chain attacks.

Lumen suggests some activity may have targeted overseas Chinese users accessing mainland services through the SpeedCN VPN. While the campaign has not been attributed to a specific threat actor or known cluster, researchers note that the targeting patterns are consistent with China-aligned operations.

Lumen has published indicators of compromise to help defenders detect and block BambooToken activity. Organizations running mobile app backends, legal, financial, or software development infrastructure should monitor for unusual outbound MQTT broker connections and audit software supply chains for unauthorized side-loaded components.