CTIPilot

BambooToken

malware · malware:bambootoken single-source

Previously undocumented cross-platform (Windows/Linux) malware framework using the MQTT publish/subscribe protocol for command and control, sideloaded via a signed Tendyron OnKey USB hardware-token utility or masquerading as Kingsoft Office; active since February 2023 and observed through July 2026, unattributed but assessed China-aligned by targeting pattern (Lumen Black Lotus Labs, 2026-09-15).

Coverage timeline
1
first 2026-09-16 → last 2026-09-16
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
9
pinned v19.2 · see below

ATT&CK techniques

9 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Execution TA0002

T1047Windows Management Instrumentation×1

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

Discovery TA0007

T1082System Information Discovery×1

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

T1518.001Software Discovery: Security Software Discovery×1

Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

Command and Control TA0011

T1071.005Application Layer Protocol: Publish/Subscribe Protocols×1

Adversaries may communicate using publish/subscribe (pub/sub) application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload · ATT&CK page ↗

Story timeline

  1. 2026-09-16BambooToken, a previously undocumented MQTT-based malware framework sideloads via a signed Chinese hardware-token utility to control Windows and Linux hosts
    active-threatsLumen: an unattributed cluster hides its command-and-control behind an IoT messaging broker so infected hosts never talk to the attacker directly

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (50%)
  • lumen.com1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about BambooToken (1)

2026-09-16 · view entry permalink →

NOTABLENATOB2

BambooToken, a previously undocumented MQTT-based malware framework sideloads via a signed Chinese hardware-token utility to control Windows and Linux hosts

Lumen's Black Lotus Labs disclosed BambooToken on 2026-09-15: an emerging, previously undocumented malware framework that, based on embedded artifacts, has been active since at least February 2023 and continued through July 2026 (Lumen Black Lotus Labs, 2026-09-15). The most recent sample Lumen correlated to the campaign, a Linux build, was first observed in December 2025 (Lumen Black Lotus Labs, 2026-09-15). Rather than the direct HTTP callbacks its 2023 version used, the current Windows and Linux toolset communicates over MQTT, a publish/subscribe protocol built for IoT device control: infected hosts publish and subscribe to topics through a broker rather than contacting a command server directly, so a compromised machine never talks to the attacker's infrastructure at all, and the channel supports asynchronous tasking that survives temporary network disruption (Lumen Black Lotus Labs, 2026-09-15). Lumen's own review of prior campaigns found only three other malware families that have ever used MQTT for command and control (IOCONTROL, Korplug/PlugX and WailingCrab) making this a rare, not novel, technique choice.

The Windows variant is sideloaded through Tendyron's "OnKey" utility, a digitally signed USB hardware-token program that verifies cryptographic material for identity checks and is widely deployed across Chinese banking and government networks ("The Windows agent was sideloaded by the Tendyron 'OnKey' program, which validates system access by retrieving cryptographic material stored on a USB drive. This product line is popular in Chinese banking and government networks," Lumen Black Lotus Labs, 2026-09-15). One variant instead masquerades as "Zhuhai Kingsoft Office Software Co., Ltd." Lumen assesses neither Tendyron's nor Kingsoft's code-signing certificate was compromised: the OnKey binary itself is genuinely signed but merely vulnerable to sideloading rather than abused through a certificate compromise, while the Kingsoft-masquerading variant's own files fail certificate-signature validation outright, confirming that certificate was never actually applied to them (Lumen Black Lotus Labs, 2026-09-15).

Once running, the malware enumerates the host through Windows Management Instrumentation (operating system details, computer system product details, the original product key, serial number and software licensing service information) then subscribes to a global broadcast topic plus per-host, GUID-scoped topics and publishes an online/offline heartbeat carrying that GUID (Lumen Black Lotus Labs, 2026-09-15). Three command handlers have been identified: SHELL spawns a command shell, FILEEX uploads, downloads and deletes files, and ONLINE collects and beacons a separate set of host parameters, including BIOS and system details, as a heartbeat (Lumen Black Lotus Labs, 2026-09-15). A recovered plugin performs security-software discovery via WMI on a five-second timer and reports results over plain HTTP. Static "dead code" strings referencing clipboard capture, keylogging, audio recording and webcam capture were found in one sample's unexecuted code sections (Lumen Black Lotus Labs, 2026-09-15); because the detail comes from dead code, researchers cannot confidently determine whether these modules were ever operational or remain under development (BleepingComputer, 2026-09-15).

Lumen's telemetry links a dozen compromised enterprise environments mostly located in Asia, with a handful in South America (named examples include a biomedical company in Argentina and a legal firm in Chile) spanning mobile-application backends, legal and financial services, a smartwatch-adjacent software company, a hotel and a GitLab instance in Hong Kong, the last of which the report flags as a software-supply-chain concern given the developer access such a compromise could yield (Lumen Black Lotus Labs, 2026-09-15). A separate cluster of over 150 infected small-office and home routers was reached through internet-wide SNMP scanning; a handful of those IPs held persistent connections to an active C2 node over the MQTT port, and Lumen identifies the underlying devices in that handful as primarily MikroTik and DrayTek routers geolocated to Singapore, Cambodia and Vietnam. Lumen believes this pool primarily supports data collection against the Chinese diaspora rather than serving as C2 relay infrastructure (Lumen Black Lotus Labs, 2026-09-15). Command-and-control domains sit behind Cloudflare, with one domain reaching Cloudflare Radar's top 500,000 most-popular domains and an older one the top million at the height of its use, evidence of a wide, established infection base rather than a narrow test deployment (Lumen Black Lotus Labs, 2026-09-15). Lumen assesses the targeting pattern as consistent with China-aligned operations but states it cannot attribute the cluster to any publicly documented actor.

Black Lotus Labs®, the threat research division at Lumen, uncovered BambooToken, an emerging malware family using the Message Queueing and Telemetry Transport (MQTT) to quietly control infected Windows and Linux systems.

The Windows agent was sideloaded by the Tendyron “OnKey” program, which validates system access by retrieving cryptographic material stored on a USB drive. This product line is popular in Chinese banking and government networks.

Lumen does not assess that Tendyron's code signing certificate was compromised. Preliminary analysis indicates the signed executable appears benign and was vulnerable to side-loading rather than actively abused through a certificate compromise.

Lumen Black Lotus Labs 2026-09-15

This approach has the advantage that infected systems do not connect directly to the attacker’s infrastructure, which increases evasion and resilience. At the same time, communications can be asynchronous, ensuring operational continuity during temporary network disruptions.

BleepingComputer 2026-09-15
threat16 Sep 05:10Zsingle-sourceOpen finding ↗