hacker-news · Crawled Sep 15, 2026
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
3 IoCs
Read original article ↗
AI Summary
BambooToken is a multi-platform malware family active since at least February 2023, targeting organizations in Asia and South America. It uses the MQTT protocol for command-and-control (C2) communications, leveraging DLL sideloading of Tendyron's OnKeyToken software to execute on Windows and Linux systems. The malware collects extensive host information, including antivirus details via WMI, and communicates with C2 servers hosted behind Cloudflare, indicating large-scale data collection operations. Recent activity was observed as of July 2026, with infrastructure linked to IP addresses in Singapore, Cambodia, and Vietnam.
AI-extracted · verify before operational use