New BambooToken Malware Hijacks IoT Protocol to Control Windows and Linux Machines
Security researchers at Lumen Black Lotus Labs have disclosed a previously undocumented malware campaign called BambooToken, active since at least February 2023 and still seen as recently as July 2026. The malware targets both Windows and Linux systems and has largely evaded detection, suggesting a skilled and patient threat actor is behind it.
The attackers reportedly sideloaded malicious agents through Tendyron's 'OnKey' software, a legitimate hardware token product used for identity verification in high-security environments such as banking and government sectors in China. There is no evidence that Tendyron's official code-signing certificate or build systems were compromised; instead, the attackers appear to exploit a vulnerable binary susceptible to DLL sideloading, a technique where malicious code is loaded through a trusted, legitimately signed program. Most known BambooToken samples were uploaded to VirusTotal from Chinese IP addresses, pointing to a data collection operation likely focused on users in that region.
BambooToken's use of MQTT, a lightweight protocol typically used for Internet of Things (IoT) communication, for command-and-control is notable but not unprecedented. Similar techniques were seen in 2023 with the Mustang Panda-linked MQsTTang backdoor, though MQTT-based malware remains rare overall. The initial method used to deliver BambooToken to victim networks is still unknown.