Researchers uncovered BambooToken, a multi-platform malware campaign that uses MQTT for command-and-control to target Windows and Linux systems across Asia and South America. The campaign appears to rely on DLL sideloading through Tendyron OnKey software, with infrastructure and targeting suggesting extensive data collection and possible China-linked activity. #BambooToken #Tendyron #OnKey #MQTT #MustangPanda #Cloudflare
Keypoints
- BambooToken has been active since at least February 2023.
- The malware uses MQTT as a covert command-and-control channel.
- Early attacks focused on Windows, and later versions added Linux support.
- The campaign likely uses DLL sideloading through Tendyron OnKey software.
- Victims include organizations in Asia and South America across multiple sectors.
Read More: https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html