BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2

BambooToken Malware Uses MQTT Protocol for Cross-Platform (TL-2026-2520) is a high-severity malware campaign, first published 2026-09-15. It is linked to a China-nexus actor with medium confidence, affects Tendyron OnKey (OnKeySrv authentication client software), maps to 17 MITRE ATT&CK techniques (T1005, T1016.001, T1027), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2520

Threat ID
TL-2026-2520
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-09-15
Last reviewed
2026-09-15
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
technology, mobile-applications, manufacturing, hospitality, biomedical, legal, cryptocurrency, finance
Target regions
Asia, Southeast Asia, 005 - South America, Europe
Detection rules
9
Indicators of compromise
24

Malware and tooling in BambooToken Malware Uses MQTT Protocol for Cross-Platform

Malware and tooling: BambooToken, Tendyron, Mosquitto, SoftEther VPN

BambooToken is a multi-platform (Windows and Linux) malware family active since at least February 2023 that uses the MQTT publish-subscribe protocol as its C2 channel, delivered in part via DLL side-loading of a vulnerable Tendyron OnKey banking-security-token binary, and has compromised roughly a dozen organizations across Asia and South America through July 2026.

How BambooToken Malware Uses MQTT Protocol for Cross-Platform works

BambooToken is a cross-platform malware family, initially Windows-only and expanded to Linux as of December 2025, that stands out for using the MQTT (Message Queuing Telemetry Transport) publish-subscribe protocol -- normally used for IoT telemetry -- as its command-and-control channel rather than conventional HTTP(S) C2. Lumen's Black Lotus Labs, which discovered the family after samples surfaced on VirusTotal in January 2026, documented the operation in the report 'The Banana Stand: Brokering and Managing Infections Across Asia Using MQTT.' The malware implements MQTT via the open-source Eclipse Mosquitto library; the broker architecture means the compromised host never communicates directly with the operators' server, only with the broker, which relays messages by GUID-scoped topic.

The primary observed delivery mechanism is DLL side-loading through Tendyron's OnKey software: the operators abuse the legitimate, validly-signed OnKeySrv.exe (used with Tendyron's PKI USB banking security tokens, popular in Chinese banking and government networks) to load a malicious OnKeyToken_KEB.dll. Initial execution begins with a file named Update.log, which spawns a remote thread and injects the payload into memory (process injection) rather than executing from disk directly. Black Lotus Labs also documented a secondary delivery variant impersonating 'Zhuhai Kingsoft Office Software Co., Ltd.' -- a legitimate Chinese office-suite vendor -- via a forged code signature; the researchers confirmed the threat actors did not obtain Zhuhai's actual code-signing certificate, and signature validation on the impersonating component fails, ruling out a supply-chain compromise of either Tendyron or Zhuhai and pointing instead to invalid/spoofed code-signature masquerading.

Once running, BambooToken extracts its C2 address from OnKeySrv.dat configuration files (parsing markers '&#'/'#&' for the C2 IP and '$@'/'@$' for beacon host profiles) or falls back to a hardcoded, XOR-encoded address; multiple samples share the same XOR key, letting Black Lotus Labs cluster them. A hardcoded, XOR-decoded GUID (e.g. '{5861573B-FF85-4C7A-BBAD-EFC01540357D}' in Version 1, '{534E19D5-434B-4cad-A0C2-8D75E0B2FBFC}' in the Linux Version 2.1) is used as a mutex to prevent multiple concurrent agent instances on the same host. The malware supports three command handlers over MQTT: SHELL (spawns a command shell in a new thread), FILEEX (download, upload, and delete files, plus stop-execution/exit), and ONLINE (a heartbeat beacon carrying extensive host enumeration). Version 2.0 (Windows) added a GUID-scoped topic structure (Plugin/unPlugin/removePlugin) and Version 2.1 (Linux) added an additional 'LUA' topic. Static analysis recovered dead, unused code referencing planned-but-unshipped plugins -- KEY_RECOURD (keylogger), COM_clipboard, and COM_ modules for audio, webcam, and desktop-screen capture -- indicating the plugin architecture evolved from a monolithic 2023 build toward a modular 2024+ design.

A dedicated Windows plugin uses WMI (Windows Management Instrumentation), polling roughly every five seconds, to enumerate installed antivirus products and exfiltrate the inventory via an HTTP GET request (not MQTT) to api80.c2iznja[.]com with a spoofed 'HTTP Downloader' user agent -- a defense-evasion and environment-profiling step ahead of further activity. The malware also queries the external service icanihazip[.]com to resolve its own public IP address.

Infrastructure analysis found a SoftEther VPN connection from a Virtual Private Server in Hong Kong to the C2 node at 202.144.192[.]149 -- Black Lotus Labs assesses SoftEther VPN usage originating from Hong Kong VPS infrastructure as 'a known TTP of various PRC-aligned actors,' and correlated timing between China Mobile IP connections to that SoftEther endpoint and subsequent C2 activity, though the entity behind the China Mobile address itself was not identified. Separately, a December 2025 SNMP (port 161) scanning campaign hit over 150 unique MikroTik and DrayTek router IPs across Southeast Asia in a single day; a subset showed sustained MQTT (port 1883) connections to BambooToken C2 nodes afterward, indicating successful compromise and use as relay/proxy infrastructure. Routers in Singapore, Cambodia, and Vietnam were also observed connecting via 'speedCN,' a VPN service marketed to overseas Chinese users for accessing mainland Chinese websites, suggesting a diaspora-population targeting angle. Multiple C2 domains (including cache.c2iznja[.]com and several chat5188[.]tk subdomains) sit behind Cloudflare, obscuring true origin infrastructure; chat5188[.]tk reached Cloudflare Radar's top 1,000,000 domains by December 2024 and c2iznja[.]com reached the top 500,000 by December 2025, which the researchers cite as evidence of an operator experienced at running wide-reaching campaigns.

Attribution is assessed as PRC-aligned with medium-high confidence, based on: the majority of samples being uploaded from Chinese IP space with corresponding China-based C2 telemetry; use of Tendyron OnKey tokens common in Chinese banking/government environments; the SoftEther-VPN-from-Hong-Kong TTP; deliberate anti-forensic operational security (forged PE compilation metadata claiming Windows Server 2003/Visual Studio 2005 with intentionally varied timestamps to prevent signature clustering); and a targeting pattern -- testing capability against discreet regional/diaspora targets before likely broader expansion -- that mirrors the historical playbook of PRC-nexus actors such as Volt Typhoon, GhostEmperor, and ZuoRAT. Shared RichPE header data across 2024 and 2025 campaign samples indicates a common codebase and development environment maintained by the same operator over time. No specific named threat actor or group was attributed, and Black Lotus Labs found no technical overlap with PlugX/Korplug despite both malware families having used MQTT-adjacent or MQTT-based channels historically; researchers describe BambooToken as an 'emerging threat cluster' with no public correlation to previously documented activity.

Approximately a dozen compromised entities were identified during the investigation, spanning several mobile-application backend servers, a GitLab server in Hong Kong, a portable-lifestyle-device manufacturer and a hotel in Vietnam, a biomedical company in Argentina, a legal firm in Chile, a cryptocurrency website in Lithuania, and a financial organization in Malaysia. The concentration of mobile-application-server victims suggests an extensive data-collection operation. Researchers noted BambooToken sits in a small cohort of malware families that abuse MQTT for C2, alongside MQsTTang (Mustang Panda/CeranaKeeper, 2023), Tizi (Android spyware, in some C2 modes), WailingCrab/WikiLoader (Bamboo Spider cybercrime group), and IOCONTROL/OrpaCrab (Iran-linked OT/IoT malware) -- named by the source reporting as comparators, not as related campaigns.

MITRE ATT&CK techniques used in TL-2026-2520

Collection

T1005 Data from Local System

Discovery

T1016.001 Internet Connection Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036.001 Invalid Code Signature; T1055 Process Injection; T1070.004 File Deletion; T1574.001 DLL

Execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1129 Shared Modules

Command and Control

T1071.005 Publish/Subscribe Protocols; T1090.002 External Proxy; T1571 Non-Standard Port

Resource Development

T1584.008 Network Devices

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in BambooToken Malware Uses MQTT Protocol for Cross-Platform

  • Tendyron — OnKey (OnKeySrv authentication client software)
    Vulnerable versions: unspecified in source reporting -- affects environments with the OnKeySrv.exe binary installed
  • MikroTik — RouterOS devices (compromised via SNMP scanning and used as BambooToken C2 relay infrastructure)
    Vulnerable versions: unspecified -- compromise vector observed as SNMP (port 161) scanning followed by sustained MQTT/1883 connections
  • DrayTek — Routers (compromised via SNMP scanning and used as BambooToken C2 relay infrastructure)
    Vulnerable versions: unspecified -- compromise vector observed as SNMP (port 161) scanning followed by sustained MQTT/1883 connections

Remediation for BambooToken Malware Uses MQTT Protocol for Cross-Platform

Patches

  • No vendor patch for the OnKeySrv DLL side-loading behavior was identified in the source reporting; contact Tendyron for guidance on hardening the OnKey client

Immediate actions

  • Block the known C2 domains (chat5188.tk and its subdomains; c2iznja.com and its subdomains including api80, live-hk, turbo, cache) and C2 IPs (202.144.192.149, 210.1.231.13, 38.180.150.19) at DNS/proxy/perimeter layers
  • Hunt for OnKeyToken_KEB.dll alongside a legitimate OnKeySrv.exe, for Update.log performing remote-thread process injection, and for any unexpected DLL dropped into the Tendyron OnKey install directory
  • Audit egress traffic for MQTT (TCP/1883, TCP/2883, TLS/8883) connections from hosts with no legitimate IoT/telemetry use case, and for outbound HTTP GET requests to api80.c2iznja.com with a 'HTTP Downloader' user agent
  • Inventory internet-exposed MikroTik and DrayTek routers, close/restrict SNMP (UDP/TCP 161) to management networks, and rotate credentials; check for sustained outbound MQTT/1883 sessions from router management VLANs
  • Scan for the SHA256 samples and validate any binary claiming to be signed by Tendyron or by 'Zhuhai Kingsoft Office Software Co., Ltd.' against the vendors' actual, current signing certificates

Workarounds

  • Restrict or remove the Tendyron OnKey client from systems that do not require PKI banking-token authentication
  • Block outbound MQTT (1883/2883/8883) by default and allow-list only sanctioned brokers

Longer-term hardening

  • Deploy EDR/NDR signatures for MQTT-based C2 (publish/subscribe traffic to non-enterprise brokers, GUID-scoped topic patterns) rather than relying solely on HTTP(S)-centric detection
  • Apply DLL side-loading mitigations (safe DLL search mode, code integrity / WDAC rules, binary allow-listing) on hosts running third-party PKI/authentication client software such as Tendyron OnKey
  • Monitor for SoftEther VPN client activity originating from unexpected VPS/cloud egress points, particularly Hong Kong-hosted infrastructure
  • Segment and monitor router management interfaces (SNMP, MQTT egress) separately from general network egress to detect abuse as C2 relay infrastructure
  • Alert on mismatched/invalid code-signature chains rather than only on the presence or absence of a digital signature

Weaknesses (CWE) in BambooToken Malware Uses MQTT Protocol for Cross-Platform

CWE-427

Timeline of BambooToken Malware Uses MQTT Protocol for Cross-Platform

  • BambooToken Version 1 (Windows-only) is first observed active in the wild, the earliest known activity for the campaign against organizations in Asia and South America.
  • The chat5188.tk C2 domain family climbs into Cloudflare Radar's top 1,000,000 domains, an indicator Black Lotus Labs cites as evidence of a mature, wide-reaching campaign.
  • BambooToken operators begin porting the malware to Linux (Version 2.1), giving the family its current cross-platform Windows/Linux capability.
  • A large-scale SNMP (port 161) scanning campaign hits over 150 unique MikroTik and DrayTek router IPs across Southeast Asia in a single day (0730-2345 UTC), identifying candidate devices for later compromise and use as C2 relay infrastructure.
  • The newer c2iznja.com C2 domain family reaches Cloudflare Radar's top 500,000 domains.
  • BambooToken samples surface on VirusTotal, giving Lumen's Black Lotus Labs the initial lead used to begin tracking the campaign.
  • The c2iznja.com C2 domain family becomes the malware's primary infrastructure and the first victim check-ins against it are observed.
  • The Linux ELF variant (protocol Version 2.1, adding a 'LUA' MQTT topic) is compiled and deployed.
  • Secondary C2 node activity begins, including first contact from the SoftEther VPN-connected VPS later identified in Hong Kong.
  • Continued BambooToken operations are observed on tertiary C2 nodes through this date, part of the most recent activity window in the campaign.
  • Last observed victim activity tied to the SoftEther VPN VPS in Hong Kong, the most recent known point in the campaign as of the published report.
  • Lumen's Black Lotus Labs publishes 'The Banana Stand: Brokering and Managing Infections Across Asia Using MQTT,' covered the same day by The Hacker News.

Sources cited for BambooToken Malware Uses MQTT Protocol for Cross-Platform

More in malware

Detection coverage for TL-2026-2520

As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2520 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats