BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL Side-Loading and Kingsoft Office Impersonation
BambooToken: Cross-Platform Windows/Linux Malware Using MQTT (TL-2026-2519) is a high-severity malware campaign, first published 2026-09-15. It is linked to a China-nexus actor with low confidence, affects Tendyron Corporation OnKey USB-token utility (digitally signed, maps to 14 MITRE ATT&CK techniques (T1005, T1036.005, T1056.001), and is covered by 9 detection rules and 9 indicators of compromise.
Key facts for TL-2026-2519
- Threat ID
- TL-2026-2519
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-15
- Last reviewed
- 2026-09-15
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- hospitality, biomedical, legal, financial services, cryptocurrency, technology, software development devops
- Target regions
- Asia, 005 - South America, Europe
- Detection rules
- 9
- Indicators of compromise
- 9
Malware and tooling in BambooToken: Cross-Platform Windows/Linux Malware Using MQTT
Malware and tooling: BambooToken, BambooToken v2.1 (Linux), Kingsoft Office / WPS Office (impersonated), MQTT broker-based command-and-control, Tendyron OnKey USB-token utility (digitally signed, abused for DLL side-loading)
BambooToken is a cross-platform (Windows and Linux) malware framework active since 2023 that uses the MQTT IoT messaging protocol for command-and-control, letting infected hosts subscribe to attacker-published broker topics instead of connecting directly to attacker infrastructure. Lumen's Black Lotus Labs identified roughly a dozen compromised entities across Asia and South America, delivered via DLL side-loading of a digitally signed Tendyron OnKey USB-token utility and impersonation of the Kingsoft Office suite, with targeting patterns consistent with China-aligned operations.
How BambooToken: Cross-Platform Windows/Linux Malware Using MQTT works
BambooToken is a malware family tracked by Lumen's Black Lotus Labs that has been active since at least 2023 and gained an MQTT-based command-and-control transport in its 2024-2025 variant lineage. Rather than beaconing directly to attacker-controlled infrastructure, infected Windows and Linux hosts subscribe to unique-identifier topics on a central MQTT broker while the attacker publishes tasking to those same topics; this broker-mediated, topic-based design lets the operators issue commands asynchronously, survive network disruption, and avoid exposing a fixed C2 endpoint to defenders monitoring for direct outbound callbacks. The newest confirmed variant, BambooToken v2.1 for Linux, was observed in December 2025 and demonstrates ongoing active development; per Black Lotus Labs it retains MQTT communications alongside system enumeration, remote command-shell spawning, and file upload/download/delete operations carried out over the same C2 channel.
Initial delivery relies on two techniques: DLL side-loading of a legitimately, digitally signed Tendyron OnKey USB-token utility, and masquerading as the Kingsoft Office productivity suite. The Tendyron OnKey side-loading vector is notable because the same signed-binary family (Tendyron.exe alongside a malicious OnKeyToken_KEB.dll placed to win Windows' DLL search order) was previously documented by ESET in 2022 as the first-stage loader used by the China-aligned TA410 umbrella / FlowingFrog cluster to deploy the FlowCloud backdoor via shellcode injected into iexplore.exe. BambooToken's reuse of the same abusable signed Tendyron software as a side-loading carrier is consistent with, though not proof of, the China-aligned targeting pattern Black Lotus Labs describes for this campaign; researchers were unable to reach a definitive actor attribution.
Black Lotus Labs identified roughly a dozen compromised organizations concentrated in Asia and South America. Confirmed or reported victim types include hotels, biomedical firms, law firms, financial organizations, a Lithuania-based cryptocurrency website, mobile application backend infrastructure (the most commonly affected victim category), and a GitLab server in Hong Kong assessed to carry supply-chain attack potential given GitLab's role hosting source code and CI/CD pipelines. Researchers also flagged a possible link to targeting of the SpeedCN VPN service, suggesting an interest in overseas Chinese VPN users consistent with an espionage-oriented, rather than purely financial, motivation.
Static analysis surfaced strings in dead/inactive code sections referencing antivirus-product enumeration, keylogging, clipboard theft, audio recording, webcam capture, and screenshot capture. Black Lotus Labs could not confirm whether these modules are operational, dormant, or still under development, so they are documented here as an identified-but-unconfirmed capability set rather than observed active behavior. No CVE or CVSS score applies to this threat: BambooToken is a malware delivery and C2 framework abusing legitimate signed software and MQTT infrastructure rather than a specific software vulnerability. Lumen states it has shared indicators of compromise to help defenders detect and block the activity.
MITRE ATT&CK techniques used in TL-2026-2519
Collection
T1005 Data from Local System; T1056.001 Keylogging; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion; T1574.001 DLL
Execution
T1059.003 Windows Command Shell; T1059.004 Unix Shell; T1204.002 Malicious File
Command and Control
T1071 Application Layer Protocol
Discovery
T1082 System Information Discovery; T1518.001 Security Software Discovery
Affected products and versions in BambooToken: Cross-Platform Windows/Linux Malware Using MQTT
- Tendyron Corporation — OnKey USB-token utility (digitally signed installer/executable)
Vulnerable versions: Abused as a DLL side-loading carrier via DLL search-order hijacking; not a version-specific software flaw in the legitimate product
Fixed in: Not applicable - mitigation is application allow-listing / blocking untrusted companion DLLs, not a vendor patch - Kingsoft — Kingsoft Office / WPS Office (impersonated by the malware, not itself exploited)
Vulnerable versions: Not applicable - malware masquerades as this application; the legitimate suite is not exploited
Fixed in: Not applicable
Remediation for BambooToken: Cross-Platform Windows/Linux Malware Using MQTT
Patches
- No vendor patch applies: BambooToken abuses a legitimately signed Tendyron OnKey binary for DLL side-loading rather than exploiting a disclosed software vulnerability, and no CVE has been assigned to this activity.
Immediate actions
- Alert on and inspect outbound MQTT traffic (broker connect/subscribe/publish activity) originating from endpoints that have no legitimate business reason to use IoT messaging protocols.
- Hunt for Tendyron.exe or other Tendyron OnKey-branded binaries executing outside expected online-banking-token security contexts, especially where paired with an unsigned or unexpectedly located companion DLL such as OnKeyToken_KEB.dll.
- Inspect hosts for files or installers masquerading as Kingsoft Office / WPS Office components that do not match the legitimate vendor's digital signature or standard install path.
- Prioritize triage of the victim sectors and infrastructure types Black Lotus Labs identified: hospitality, biomedical, legal, financial, cryptocurrency, mobile-app backend, and DevOps/source-control (GitLab) infrastructure.
Workarounds
- Restrict installation and execution of Tendyron OnKey and Kingsoft Office software to verified, vendor-distributed packages obtained through trusted channels only.
- Enforce write-protection on application install directories to prevent planting of malicious companion DLLs alongside legitimate signed executables.
Longer-term hardening
- Deploy application allow-listing / execution-control policies that block untrusted companion DLLs from loading alongside legitimately signed third-party utilities, to close the DLL side-loading vector generally, not just for Tendyron OnKey.
- Add detection content for MQTT-based command-and-control (broker connections to non-corporate destinations, topic subscribe/publish patterns, non-standard MQTT client processes) to network security monitoring and EDR.
- Establish a software supply-chain vetting process for third-party USB-token / OTP vendor utilities before enterprise deployment, given the abuse of signed Tendyron OnKey software as a side-loading carrier.
- Monitor GitLab and other DevOps/CI-CD infrastructure for anomalous credential use, pipeline modification, or code-push activity given the identified supply-chain risk at the compromised Hong Kong GitLab server.
Timeline of BambooToken: Cross-Platform Windows/Linux Malware Using MQTT
- ESET publicly documents the China-aligned TA410/FlowingFrog cluster abusing the same Tendyron.exe + OnKeyToken_KEB.dll DLL side-loading technique to deploy the FlowCloud backdoor, establishing prior precedent for this delivery vector.
- BambooToken malware family first becomes active, per Lumen Black Lotus Labs tracking (year-level precision only; exact month not disclosed in the source).
- BambooToken variants begin adopting MQTT as the command-and-control transport, within the 2024-2025 window Black Lotus Labs describes (date is an approximate midpoint of the disclosed range, not a precise observation date).
- BambooToken v2.1 for Linux is observed, the latest confirmed variant, indicating active ongoing development of the malware.
- BleepingComputer reports on the Black Lotus Labs BambooToken research, making the findings broadly public.
- Lumen shares indicators of compromise from its BambooToken research to help defenders detect and block the activity.
- Lumen's Black Lotus Labs publishes research on BambooToken, documenting roughly a dozen compromised entities across Asia and South America.
Sources cited for BambooToken: Cross-Platform Windows/Linux Malware Using MQTT
- BambooToken malware controls Windows and Linux systems via MQTT
- A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity (Tendyron.exe / OnKeyToken_KEB.dll DLL side-loading to FlowCloud)
- Black Lotus Labs | Lumen Technologies (threat research publication hub)
- Black Lotus Labs indicators-of-compromise repository
- herdProtect signer analysis: Tendyron Corporation
- SpyShelter analysis: OnKey_Install_Silent.exe (Tendyron)
More in malware
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
Detection coverage for TL-2026-2519
As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2519 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.