BambooToken is a previously unknown malware framework active since at least 2023 that now uses MQTT for command-and-control on Windows and Linux systems. Black Lotus Labs found it in campaigns targeting enterprise servers and infrastructure used by mobile apps, legal and financial services, with signs of possible China-aligned operations. #BambooToken #MQTT #BlackLotusLabs #TendyronOnKey #KingsoftOffice #GitLab
Keypoints
- BambooToken has been active since at least 2023.
- Its newer variants use MQTT for command-and-control communication.
- The malware infects Windows and Linux systems through software impersonation and sideloading.
- Researchers found signs of keylogging, clipboard theft, audio recording, webcam capture, and screenshots in the code.
- Targets included enterprise servers, mobile app backends, and a GitLab server in Hong Kong.