
BambooToken Malware Uses MQTT C2 and Tendyron OnKey DLL Sideloading on Windows and Linux Since February 2023
BambooToken is a multi-platform implant active since 2023 that uses MQTT for C2 and Tendyron OnKey DLL sideloading. Evidence from VirusTotal submissions and code evolution shows steady expansion to Linux without confirmed attribution. The campaign targets Asian and South American organizations likely to have the abused authentication software installed.
Initial access remains unknown but operators sideload OnKeyToken_KEB.dll into Tendyron's OnKeySrv.exe, a PKI USB token binary used in Chinese financial and government environments. Early variants ran via PowerShell stagers allocating memory for the agent; later builds rely on the DLL hijack to reduce EDR visibility while maintaining the same MQTT loop.
MQTT usage mirrors Mustang Panda's MQsTTang backdoor from January 2023 and the later IOCONTROL OT malware, yet BambooToken samples uploaded predominantly from Chinese IP space show no code overlap with those families. The actor's choice of a protocol common in IoT and SCADA suggests intent to blend with legitimate telemetry traffic rather than nation-state attribution.
Subsequent versions added Linux support by December 2025 while retaining the same four MQTT command set. Upload timestamps and target geography point to a data-collection focus on regional banking and government networks that already deploy Tendyron hardware tokens.
No independent technical attribution exists beyond the observed binary artifacts and C2 infrastructure; official statements from Lumen stop at capability description.
Black Lotus Labs: BambooToken will add at least one new MQTT plugin for OT protocol enumeration on Linux hosts before July 2027.
Sources (2)
- [1]Primary Source(https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html)
- [2]Supporting Source(https://blog.lumen.com/black-lotus-labs-bambootoken-mqtt)