Last updated: October 5, 2026 at 10:28 AM UTC
All 897 Vulnerability 362 Breach 144 Threat 384 Defense 7
Tag: cross-platform (2 articles)Clear

Stealthy BambooToken malware controls Windows and Linux over the IoT MQTT protocol

Researchers at Black Lotus Labs detailed BambooToken, a stealthy malware framework active since at least 2023 that controls infected Windows and Linux systems using MQTT, a lightweight messaging protocol designed for internet-of-things devices. Instead of connecting directly to attacker servers, infected machines subscribe to topics on a message broker, and operators publish commands to them, which helps evade detection and keeps working through network disruptions. The malware is installed by side-loading a malicious library through a legitimately signed USB-token tool or by impersonating office software. It compromised about a dozen enterprises, including a source-code server, and researchers note that command-and-control over an uncommon protocol like MQTT is an easy blind spot.

Check
Monitor servers and workstations for unexpected MQTT or message-broker traffic, watch for signed programs side-loading unexpected libraries, and add uncommon command-and-control protocols to your detection and network-monitoring coverage.
Affected
Windows and Linux enterprise systems tricked into side-loading the malware through signed software or office-suite impersonation; once infected, they take commands over MQTT, an IoT protocol many defenses do not inspect.
Fix
Restrict and monitor outbound traffic to unexpected message brokers and MQTT ports, enforce application control against DLL side-loading, verify signed software supply chains, and hunt for the campaign's indicators across hosts.

QuimaRAT rents out a cross-platform Java trojan for Windows, Linux, and macOS

LevelBlue detailed QuimaRAT, a new Java-based remote access trojan sold as a service that runs across Windows, Linux, and macOS from the same codebase. Subscriptions range from about $150 for a month to $1,200 for lifetime access, lowering the bar for attackers to get cross-platform reach. Built around a modular design, it expands its capabilities through encrypted plugins that operators can load, update, or remove from their command server on the fly. It also uses several obfuscation techniques to keep changing how it looks to security tools without altering its behavior, so signatures based on its appearance are likely to go stale quickly.

Check
Ensure endpoint protection covers Linux and macOS as well as Windows, watch for unexpected Java processes and outbound command-and-control traffic, and be wary of behavior-independent signatures given this malware's shifting fingerprints.
Affected
Organizations running mixed Windows, Linux, and macOS fleets; QuimaRAT's single cross-platform codebase and rented model let even low-skill attackers gain modular remote access across all three operating systems.
Fix
Deploy endpoint detection across all operating systems including macOS and Linux, prioritize behavior-based detection over static signatures, restrict unnecessary Java runtimes, and monitor for encrypted plugin traffic to unfamiliar command-and-control servers.