bleeping-computer · Crawled Sep 15, 2026

BambooToken malware controls Windows and Linux systems via MQTT

Read original article ↗

AI Summary

BambooToken is a previously unknown malware framework active since at least 2023 that uses the MQTT protocol for command-and-control communications on both Windows and Linux systems. It has been observed compromising enterprise servers in Asia and South America, including those supporting mobile apps, legal and financial services, and software development. The malware is capable of keylogging, clipboard theft, audio and webcam capture, and file manipulation, with a Linux variant (version 2.1) observed in December 2025. While no specific threat actor is attributed, targeting patterns suggest alignment with China-aligned operations.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.