BambooToken malware uses MQTT C2 on Windows and Linux systems
Malware Activity
Summary
Hide ▲
Show ▼
BambooToken is a multi-platform malware campaign using MQTT for command-and-control on Windows and Linux systems. Lumen Black Lotus Labs says the activity has been active since at least February 2023, was observed again in July 2026, and uses Tendyron OnKey software for DLL sideloading via OnKeyToken_KEB.dll. The campaign targets organizations across Asia and South America and includes infrastructure such as chat5188[.]tk and api80.c2iznja[.]com. Lumen assesses the activity is geared toward extensive data collection.
Related Happenings
Sality botnet payload distribution and propagation activity
Malware Activity
H score62
First: 02.09.2026 09:56
Last: 02.09.2026 09:56
Sources 1
About this happening:
The Sality P2P botnet has operated for more than 20 years and was disrupted in a US-led operation on August 31 with support from Bulgaria, Hungary, Romania, Euro...
Sality botnet payload distribution and propagation activity
Malware ActivityAbout this happening: The Sality P2P botnet has operated for more than 20 years and was disrupted in a US-led operation on August 31 with support from Bulgaria, Hungary, Romania, Euro...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor Meta
H score28
First: 03.08.2026 23:01
Last: 03.08.2026 23:01
Sources 1
About this happening:
DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
DOUBLECUP loader-as-a-service expands ClickFix campaign tooling for Windows and macOS
Threat Actor MetaAbout this happening: DOUBLECUP is a Russian loader-as-a-service that packages ClickFix campaign tooling and has been active since early June 2026, according to SOCRadar. It supplie...
Millenium RAT Windows malware activity and native C++ rewrite
Malware Activity
H score62
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...
Millenium RAT Windows malware activity and native C++ rewrite
Malware ActivityAbout this happening: The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...
Easy-day-js malware delivery through poisoned Mastra packages
Malware Activity
H score29
First: 22.06.2026 14:30
Last: 22.06.2026 14:30
Sources 1
About this happening:
A poisoned Mastra package chain delivered malware through easy-day-js, creating compromise risk across Windows, MacOS and Linux systems. The payload disabled TLS...
Easy-day-js malware delivery through poisoned Mastra packages
Malware ActivityAbout this happening: A poisoned Mastra package chain delivered malware through easy-day-js, creating compromise risk across Windows, MacOS and Linux systems. The payload disabled TLS...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Timeline
-
15.09.2026 18:00 3 articles · 2h ago
BambooToken malware uses MQTT command-and-control on Windows and Linux systems
Initial DisclosureBambooToken, a previously unknown malware framework active since at least 2023, uses MQTT for command-and-control on Windows and Linux systems. Variants developed between 2024 and 2025 spread by side-loading digitally signed Tendyron OnKey USB-token software or by impersonating the Kingsoft Office productivity suite, and the activity was tied to approximately a dozen compromised enterprise entities, mostly in Asia and South America, plus a GitLab server in Hong Kong. The malware publishes status and system information through the broker, receives operator instructions through subscribed topics, and Lumen shared IoCs to help defenders detect and block the activity.
Show sources
- BambooToken malware controls Windows and Linux systems via MQTT — www.bleepingcomputer.com — 15.09.2026 18:00
- BambooToken malware controls Windows and Linux systems via MQTT — www.bleepingcomputer.com — 15.09.2026 18:00
- BambooToken Malware Uses MQTT to Control Windows and Linux Systems — thehackernews.com — 15.09.2026 18:23