#BambooToken
Linux servers now facing MQTT-based backdoor called BambooToken that hides commands and exfiltrates files. #MQTT #Linux #Backdoor #C2 #CyberSecurity #ThreatIntel https://thedailytechfeed.com/new-bambootoken-linux-backdoor-leverages-mqtt-for-remote-control/
September 22, 2026 at 12:53 PM
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.
www.bleepingcomputer.com
September 15, 2026 at 3:00 PM
BambooToken Malware Uses MQTT Protocol to Control Windows and Linux Systems and Evade Detection

huntaegis.com
September 18, 2026 at 12:41 PM
𝗕𝗮𝗺𝗯𝗼𝗼𝗧𝗼𝗸𝗲𝗻 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 𝗨𝘀𝗲𝘀 𝗠𝗤𝗧𝗧 𝘁𝗼 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 𝗮𝗻𝗱 𝗟𝗶𝗻𝘂𝘅 𝗦𝘆𝘀𝘁𝗲𝗺𝘀
Cybersecurity researchers have disclosed d...
https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html
Call us for a FREE IT Assessment! (888) 999-2709
September 21, 2026 at 9:51 PM
BambooToken: Een Nieuwe Linux Backdoor Gebruikt MQTT voor Stille Operaties

BambooToken is een nieuw ontdekte Linux backdoor die gebruikmaakt van het lichtgewicht berichtprotocol MQTT om externe commando's te ontvangen en gegevens te exfiltreren. MQTT, een protocol dat veel wordt toege...
BambooToken: Een Nieuwe Linux Backdoor Gebruikt MQTT voor Stille Operaties
BambooToken is een nieuw ontdekte Linux backdoor die gebruikmaakt van het lichtgewicht berichtprotocol MQTT om externe commando's te ontvangen en gegevens te exfiltreren. MQTT, een protocol dat veel wordt toegepast in Internet of Things-omgevingen voor berichtuitwisseling via een centrale broker, wordt door deze malware ingezet voor zijn vermogen om verbindingen te onderhouden en berichten efficiënt te routeren. Bij activering decodeert BambooToken een configuratie van 59 bytes, die informatie bevat over de MQTT broker en een specifieke groepstopic die gebruikt wordt. De backdoor maakt vervolgens verbinding met de broker via TCP-poort 2883 en registreert een offline statusbericht. Eenmaal g...
newsfacts.info
September 22, 2026 at 1:01 PM
BambooToken: Three Years of Hidden MQTT C2 Inside Enterprise Networks
BambooToken: Three Years of Hidden MQTT C2 Inside Enterprise Networks
The BambooToken malware has operated since February 2023 across roughly a dozen organizations, using the MQTT protocol for command-and-control and DLL sideloading via a legitimate signed executable to evade detection.
deafnews.it
September 20, 2026 at 4:15 PM
Inside BambooToken’s Linux implant: shell and file control over MQTT
Inside BambooToken’s Linux implant: shell and file control over MQTT | Reverser Space
BambooToken turns an MQTT broker into a remote-control hub for Linux. Behind a 59-byte configuration blob, hex-encoded topics, and repeating XOR lies a backdoor built...
app.reverser.space
September 22, 2026 at 3:43 AM
BambooToken malware has been active since early 2023, using MQTT for covert command and control to hit Windows and Linux systems across Asia and South America, likely via DLL sideloading. #MQTT #China #BambooToken
BambooToken Malware Uses MQTT To Control Windows And Linux Systems
Researchers uncovered BambooToken, a multi-platform malware campaign that uses MQTT for command-and-control to target Windows and Linux systems across Asia and South America. The campaign appears to rely on DLL sideloading through Tendyron OnKey software, with infrastructure and targeting suggesting extensive data collection and possible China-linked activity. #BambooToken #Tendyron #OnKey #MQTT...
www.hendryadrian.com
September 16, 2026 at 3:30 AM
🌎 Researchers found "BambooToken," a backdoor active since 2023 hiding commands inside IoT protocol MQTT. Hit hotels, law firms, crypto platforms across Asia + South America. Likely China-aligned. (via BleepingComputer) 5/8
September 23, 2026 at 3:25 PM
Linux版BambooTokenマルウェア、MQTT経由のC2でリモートシェルとファイル窃取を実行

Linux版バックドア「BambooToken」は、MQTTをコマンド&コントロール(C2)チャネルとして使用しており、攻撃者はブローカー経由のトピックを通じて侵害したホストのプロファイリング、シェルコマンドの実行、ファイル転送を行うことができます。 静的にリンクされたx86-64 ELFサンプルの解析によると、その
Linux版BambooTokenマルウェア、MQTT経由のC2でリモートシェルとファイル窃取を実行
Linux版バックドア「BambooToken」は、MQTTをコマンド&コントロール(C2)チャネルとして使用しており、攻撃者はブローカー経由のトピックを通じて侵害したホストのプロファイリング、シェルコマンドの実行、ファイル転送を行うことができます。 静的にリンクされたx86-64 ELFサンプルの解析によると、その
blackhatnews.tokyo
September 22, 2026 at 11:01 AM
This is fantastic: malware that uses MQTT for command and control. I looked into MQTT for a side project that never went anywhere, it's well thought out.

https://securityaffairs.com/199205/malware/bambootoken-the-malware-that-speaks-mqtt-to-stay-under-the-radar.html

#malware #c2
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar
Lumen exposes BambooToken, a stealthy 2023-era malware family using MQTT and sideloading to quietly infect targets across Asia and beyond.
securityaffairs.com
September 17, 2026 at 3:46 AM
BambooToken: la nueva botnet que explota el protocolo MQTT para eludir controles tradicionales www.disoftin.com/2026/09/bamb...
BambooToken: la nueva botnet que explota el protocolo MQTT para eludir controles tradicionales
Blog sobre seguridad de la informacion, ethical hacking, pentest
www.disoftin.com
September 16, 2026 at 1:30 AM
BambooToken Malware Uses MQTT to Control Windows and Linux Systems #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 16, 2026 at 6:01 PM
BambooTokenというLinuxマルウェア、MQTTでシェルコマンド実行とファイル窃取を実行

研究者らは、コマンド&コントロール(C2)通信にMQTTメッセージングプロトコルを使用するバックドア「BambooToken」と識別されたLinuxマルウェアの検体を分析しました。 このマルウェアは、システム情報の収集、シェルコマンドの実行、ファイルの閲覧、データのアップロード、そして侵害されたLinuxマシンからの
BambooTokenというLinuxマルウェア、MQTTでシェルコマンド実行とファイル窃取を実行
研究者らは、コマンド&コントロール(C2)通信にMQTTメッセージングプロトコルを使用するバックドア「BambooToken」と識別されたLinuxマルウェアの検体を分析しました。 このマルウェアは、システム情報の収集、シェルコマンドの実行、ファイルの閲覧、データのアップロード、そして侵害されたLinuxマシンからの
blackhatnews.tokyo
September 22, 2026 at 7:53 AM
BambooToken malware uses MQTT to control Windows and Linux systems, with agents sideloaded via Tendyron OnKey-related binaries to target organizations in Asia and South America.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 15, 2026 at 3:53 PM
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol…
#hackernews #news
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control […]
securityaffairs.com
September 17, 2026 at 6:41 PM
September 17, 2026 at 8:29 AM
BambooToken, il malware che controlla Windows e Linux via MQTT
BambooToken sfrutta MQTT per controllare sistemi Windows e Linux: sideloading, plugin, raccolta ...
https://www.ilsoftware.it/bambootoken-il-malware-che-controlla-windows-e-linux-via-mqtt/
September 16, 2026 at 10:00 AM
BambooToken malware controls Windows and Linux systems via MQTT

A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
#hackernews #news
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
www.bleepingcomputer.com
September 16, 2026 at 2:59 PM