BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines.
Most malware connects directly to a command-and-control server to receive instructions. BambooToken takes a different approach. It uses MQTT to exchange commands through a broker, making the communication less direct and potentially harder to detect.
Researchers found that the malware has been used to control compromised Windows and Linux systems and has been active since at least 2023.
“Lumen researchers at Black Lotus Labs identified a multiplatform campaign using the MQTT system for communications targeting Windows and Linux systems.” reads the Lumen report. “Based on technical artifacts, we believe this campaign was active since at least February 2023 and continued through July 2026.”
by Security Affairs – BambooToken: The Malware That Speaks MQTT to Stay Under the Radar



