Researchers at Black Lotus Labs detailed BambooToken, a stealthy malware framework active since at least 2023 that controls infected Windows and Linux systems using MQTT, a lightweight messaging protocol designed for internet-of-things devices. Instead of connecting directly to attacker servers, infected machines subscribe to topics on a message broker, and operators publish commands to them, which helps evade detection and keeps working through network disruptions. The malware is installed by side-loading a malicious library through a legitimately signed USB-token tool or by impersonating office software. It compromised about a dozen enterprises, including a source-code server, and researchers note that command-and-control over an uncommon protocol like MQTT is an easy blind spot.
Researchers detailed Cruciferra, a crypter service that packages Windows malware to evade detection using two notable techniques. It brings a vulnerable signed driver to disable security tooling, an approach known as bring-your-own-vulnerable-driver, and it uses process ghosting, where a malicious file is deleted before its code is mapped into a running process, so the running program has no backing file for tools to inspect. Together these let common payloads run while sidestepping many endpoint defenses. Crypter services matter because they lower the skill needed to deploy malware stealthily, letting many separate actors wrap their payloads in the same evasion layer rather than building it themselves.