← All articles

Stealthy BambooToken malware controls Windows and Linux over the IoT MQTT protocol

Researchers at Black Lotus Labs detailed BambooToken, a stealthy malware framework active since at least 2023 that controls infected Windows and Linux systems using MQTT, a lightweight messaging protocol designed for internet-of-things devices. Instead of connecting directly to attacker servers, infected machines subscribe to topics on a message broker, and operators publish commands to them, which helps evade detection and keeps working through network disruptions. The malware is installed by side-loading a malicious library through a legitimately signed USB-token tool or by impersonating office software. It compromised about a dozen enterprises, including a source-code server, and researchers note that command-and-control over an uncommon protocol like MQTT is an easy blind spot.

Check
Monitor servers and workstations for unexpected MQTT or message-broker traffic, watch for signed programs side-loading unexpected libraries, and add uncommon command-and-control protocols to your detection and network-monitoring coverage.
Affected
Windows and Linux enterprise systems tricked into side-loading the malware through signed software or office-suite impersonation; once infected, they take commands over MQTT, an IoT protocol many defenses do not inspect.
Fix
Restrict and monitor outbound traffic to unexpected message brokers and MQTT ports, enforce application control against DLL side-loading, verify signed software supply chains, and hunt for the campaign's indicators across hosts.