BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL Side-Loading and Kingsoft Office Impersonation

BambooToken: Cross-Platform Windows/Linux Malware Using MQTT (TL-2026-2519) is a high-severity malware campaign, first published 2026-09-15. It is linked to a China-nexus actor with low confidence, affects Tendyron Corporation OnKey USB-token utility (digitally signed, maps to 14 MITRE ATT&CK techniques (T1005, T1036.005, T1056.001), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-2519

Threat ID
TL-2026-2519
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-15
Last reviewed
2026-09-15
Attribution confidence
LOW
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
hospitality, biomedical, legal, financial services, cryptocurrency, technology, software development devops
Target regions
Asia, 005 - South America, Europe
Detection rules
9
Indicators of compromise
9

Malware and tooling in BambooToken: Cross-Platform Windows/Linux Malware Using MQTT

Malware and tooling: BambooToken, BambooToken v2.1 (Linux), Kingsoft Office / WPS Office (impersonated), MQTT broker-based command-and-control, Tendyron OnKey USB-token utility (digitally signed, abused for DLL side-loading)

BambooToken is a cross-platform (Windows and Linux) malware framework active since 2023 that uses the MQTT IoT messaging protocol for command-and-control, letting infected hosts subscribe to attacker-published broker topics instead of connecting directly to attacker infrastructure. Lumen's Black Lotus Labs identified roughly a dozen compromised entities across Asia and South America, delivered via DLL side-loading of a digitally signed Tendyron OnKey USB-token utility and impersonation of the Kingsoft Office suite, with targeting patterns consistent with China-aligned operations.

How BambooToken: Cross-Platform Windows/Linux Malware Using MQTT works

BambooToken is a malware family tracked by Lumen's Black Lotus Labs that has been active since at least 2023 and gained an MQTT-based command-and-control transport in its 2024-2025 variant lineage. Rather than beaconing directly to attacker-controlled infrastructure, infected Windows and Linux hosts subscribe to unique-identifier topics on a central MQTT broker while the attacker publishes tasking to those same topics; this broker-mediated, topic-based design lets the operators issue commands asynchronously, survive network disruption, and avoid exposing a fixed C2 endpoint to defenders monitoring for direct outbound callbacks. The newest confirmed variant, BambooToken v2.1 for Linux, was observed in December 2025 and demonstrates ongoing active development; per Black Lotus Labs it retains MQTT communications alongside system enumeration, remote command-shell spawning, and file upload/download/delete operations carried out over the same C2 channel.

Initial delivery relies on two techniques: DLL side-loading of a legitimately, digitally signed Tendyron OnKey USB-token utility, and masquerading as the Kingsoft Office productivity suite. The Tendyron OnKey side-loading vector is notable because the same signed-binary family (Tendyron.exe alongside a malicious OnKeyToken_KEB.dll placed to win Windows' DLL search order) was previously documented by ESET in 2022 as the first-stage loader used by the China-aligned TA410 umbrella / FlowingFrog cluster to deploy the FlowCloud backdoor via shellcode injected into iexplore.exe. BambooToken's reuse of the same abusable signed Tendyron software as a side-loading carrier is consistent with, though not proof of, the China-aligned targeting pattern Black Lotus Labs describes for this campaign; researchers were unable to reach a definitive actor attribution.

Black Lotus Labs identified roughly a dozen compromised organizations concentrated in Asia and South America. Confirmed or reported victim types include hotels, biomedical firms, law firms, financial organizations, a Lithuania-based cryptocurrency website, mobile application backend infrastructure (the most commonly affected victim category), and a GitLab server in Hong Kong assessed to carry supply-chain attack potential given GitLab's role hosting source code and CI/CD pipelines. Researchers also flagged a possible link to targeting of the SpeedCN VPN service, suggesting an interest in overseas Chinese VPN users consistent with an espionage-oriented, rather than purely financial, motivation.

Static analysis surfaced strings in dead/inactive code sections referencing antivirus-product enumeration, keylogging, clipboard theft, audio recording, webcam capture, and screenshot capture. Black Lotus Labs could not confirm whether these modules are operational, dormant, or still under development, so they are documented here as an identified-but-unconfirmed capability set rather than observed active behavior. No CVE or CVSS score applies to this threat: BambooToken is a malware delivery and C2 framework abusing legitimate signed software and MQTT infrastructure rather than a specific software vulnerability. Lumen states it has shared indicators of compromise to help defenders detect and block the activity.

MITRE ATT&CK techniques used in TL-2026-2519

Collection

T1005 Data from Local System; T1056.001 Keylogging; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1574.001 DLL

Execution

T1059.003 Windows Command Shell; T1059.004 Unix Shell; T1204.002 Malicious File

Command and Control

T1071 Application Layer Protocol

Discovery

T1082 System Information Discovery; T1518.001 Security Software Discovery

Affected products and versions in BambooToken: Cross-Platform Windows/Linux Malware Using MQTT

  • Tendyron Corporation — OnKey USB-token utility (digitally signed installer/executable)
    Vulnerable versions: Abused as a DLL side-loading carrier via DLL search-order hijacking; not a version-specific software flaw in the legitimate product
    Fixed in: Not applicable - mitigation is application allow-listing / blocking untrusted companion DLLs, not a vendor patch
  • Kingsoft — Kingsoft Office / WPS Office (impersonated by the malware, not itself exploited)
    Vulnerable versions: Not applicable - malware masquerades as this application; the legitimate suite is not exploited
    Fixed in: Not applicable

Remediation for BambooToken: Cross-Platform Windows/Linux Malware Using MQTT

Patches

  • No vendor patch applies: BambooToken abuses a legitimately signed Tendyron OnKey binary for DLL side-loading rather than exploiting a disclosed software vulnerability, and no CVE has been assigned to this activity.

Immediate actions

  • Alert on and inspect outbound MQTT traffic (broker connect/subscribe/publish activity) originating from endpoints that have no legitimate business reason to use IoT messaging protocols.
  • Hunt for Tendyron.exe or other Tendyron OnKey-branded binaries executing outside expected online-banking-token security contexts, especially where paired with an unsigned or unexpectedly located companion DLL such as OnKeyToken_KEB.dll.
  • Inspect hosts for files or installers masquerading as Kingsoft Office / WPS Office components that do not match the legitimate vendor's digital signature or standard install path.
  • Prioritize triage of the victim sectors and infrastructure types Black Lotus Labs identified: hospitality, biomedical, legal, financial, cryptocurrency, mobile-app backend, and DevOps/source-control (GitLab) infrastructure.

Workarounds

  • Restrict installation and execution of Tendyron OnKey and Kingsoft Office software to verified, vendor-distributed packages obtained through trusted channels only.
  • Enforce write-protection on application install directories to prevent planting of malicious companion DLLs alongside legitimate signed executables.

Longer-term hardening

  • Deploy application allow-listing / execution-control policies that block untrusted companion DLLs from loading alongside legitimately signed third-party utilities, to close the DLL side-loading vector generally, not just for Tendyron OnKey.
  • Add detection content for MQTT-based command-and-control (broker connections to non-corporate destinations, topic subscribe/publish patterns, non-standard MQTT client processes) to network security monitoring and EDR.
  • Establish a software supply-chain vetting process for third-party USB-token / OTP vendor utilities before enterprise deployment, given the abuse of signed Tendyron OnKey software as a side-loading carrier.
  • Monitor GitLab and other DevOps/CI-CD infrastructure for anomalous credential use, pipeline modification, or code-push activity given the identified supply-chain risk at the compromised Hong Kong GitLab server.

Timeline of BambooToken: Cross-Platform Windows/Linux Malware Using MQTT

  • ESET publicly documents the China-aligned TA410/FlowingFrog cluster abusing the same Tendyron.exe + OnKeyToken_KEB.dll DLL side-loading technique to deploy the FlowCloud backdoor, establishing prior precedent for this delivery vector.
  • BambooToken malware family first becomes active, per Lumen Black Lotus Labs tracking (year-level precision only; exact month not disclosed in the source).
  • BambooToken variants begin adopting MQTT as the command-and-control transport, within the 2024-2025 window Black Lotus Labs describes (date is an approximate midpoint of the disclosed range, not a precise observation date).
  • BambooToken v2.1 for Linux is observed, the latest confirmed variant, indicating active ongoing development of the malware.
  • BleepingComputer reports on the Black Lotus Labs BambooToken research, making the findings broadly public.
  • Lumen shares indicators of compromise from its BambooToken research to help defenders detect and block the activity.
  • Lumen's Black Lotus Labs publishes research on BambooToken, documenting roughly a dozen compromised entities across Asia and South America.

Sources cited for BambooToken: Cross-Platform Windows/Linux Malware Using MQTT

More in malware

Detection coverage for TL-2026-2519

As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2519 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats