importantSYS.SOURCE: The Hacker News• 2026-09-15T20:53:19+05:30
BambooToken Malware Leverages MQTT Protocol for Cross-Platform System Control
BambooToken malware employs the MQTT protocol for cross-platform command-and-control (C2) operations targeting Windows and Linux systems. The campaign uses DLL sideloading techniques and Cloudflare-based infrastructure, with suspected ties to China and extensive data collection objectives.
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.
The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
*** END OF TRANSMISSION ***