Executive Summary
BambooToken is a sophisticated multi-platform malware campaign discovered in early 2026 that uses MQTT protocol for command and control across Windows and Linux systems. Active since February 2023, the threat actors exploit DLL sideloading techniques via Tendyron's OnKey authentication software to compromise organizations across Asia and South America. The malware demonstrates advanced evasion capabilities by leveraging legitimate PKI security tokens as attack vectors and using Cloudflare-proxied infrastructure to manage infections at scale. Researchers have identified compromised entities including mobile applications, financial organizations, hotels, and critical infrastructure systems across multiple countries.
This incident highlights the evolving sophistication of threat actors who are increasingly adopting unconventional communication protocols and supply chain attack vectors to evade traditional security controls and maintain persistent access to high-value targets.
Why This Matters Now
BambooToken represents a critical evolution in attack methodology, demonstrating how threat actors are weaponizing IoT protocols and legitimate security software to bypass modern detection systems while targeting critical infrastructure and financial institutions globally.
Attack Path Analysis
BambooToken operators gained initial access through unknown vectors but leveraged Tendyron OnKey software for DLL sideloading to establish persistence on Windows and Linux systems. The malware escalated privileges through legitimate software exploitation, moved laterally across networks in Asia and South America targeting mobile apps and financial organizations. Command and control was maintained via MQTT protocol through Cloudflare-proxied infrastructure. The campaign focused on extensive data collection from compromised hosts including system information and antivirus details. Impact included widespread infection across multiple sectors for intelligence gathering and potential pattern-of-life analysis.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers delivered BambooToken malware through undetermined initial access vector, likely targeting environments with Tendyron OnKey PKI tokens installed
MITRE ATT&CK® Techniques
Hijack Execution Flow: DLL Side-Loading
Application Layer Protocol: Web Protocols
System Information Discovery
Software Discovery: Security Software Discovery
Native API
Exfiltration Over C2 Channel
Phishing
Acquire Infrastructure: Virtual Private Server
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Network Segmentation and Micro-segmentation
Control ID: NA.L2.1
PCI DSS 4.0 – Software Security Framework
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
NIS2 Directive – Incident Handling and Response
Control ID: Article 21.2(a)
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Multi-platform BambooToken malware specifically targets Tendyron PKI tokens used in Chinese financial sectors, enabling lateral movement and transaction data exfiltration through MQTT protocol.
Financial Services
MQTT-based command control threatens financial organizations' encrypted traffic and east-west security, with Malaysian finance company already compromised according to threat intelligence reports.
Government Administration
Tendyron OnKey tokens widely deployed in Chinese government sectors face DLL sideloading attacks, compromising zero trust segmentation and multicloud visibility controls.
Hospitality
Vietnamese hotel compromise demonstrates hospitality sector vulnerability to pattern-of-life analysis and travel data exfiltration through BambooToken's egress security bypassing capabilities.
Sources
- BambooToken Malware Uses MQTT to Control Windows and Linux Systemshttps://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.htmlVerified
- The Banana Stand: Brokering and Managing Infections Across Asia Using MQTThttps://www.lumen.com/blog/en-us/the-banana-stand-brokering-and-managing-infections-across-asia-using-mqttVerified
- Tendyron OnKey Product Informationhttps://www.tendyron.com/en/product/2gtoken.htmlVerified
- MQTT Protocol Official Websitehttps://mqtt.org/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have constrained BambooToken's lateral movement and C2 communications through network segmentation and egress controls. The blast radius across financial organizations and critical infrastructure would likely have been significantly reduced.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial malware deployment would likely face visibility constraints as CNSF monitoring could detect anomalous traffic patterns and unauthorized communication attempts from newly compromised endpoints
Control: Zero Trust Segmentation
Mitigation: Privilege escalation impact would likely be constrained through workload isolation policies that limit elevated process capabilities and restrict access to sensitive system resources even with compromised credentials
Control: East-West Traffic Security
Mitigation: Cross-network propagation would likely be significantly constrained as east-west traffic controls could block unauthorized inter-segment communications and prevent access to critical financial systems and mobile application infrastructure
Control: Multicloud Visibility & Control
Mitigation: C2 communication channels would likely face detection and blocking as multicloud visibility could identify suspicious MQTT traffic patterns and unauthorized VPN connections to external infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration scope would likely be reduced through controlled egress policies that restrict outbound data flows and limit unauthorized transmission of sensitive system information to external MQTT endpoints
Overall campaign impact would likely be constrained to isolated network segments with reduced access to critical financial and biomedical systems, limiting the scope of intelligence gathering and pattern-of-life analysis capabilities
Impact at a Glance
Affected Business Functions
- Financial Transaction Authentication
- Secure Workstation Access
- PKI Certificate Management
- Mobile Application Services
Estimated downtime: 7 days
Estimated loss: $500,000
Extensive host information including system details, antivirus configurations, and authentication tokens from organizations across Asia and South America. Affected entities include mobile application companies, financial organizations, hospitality systems, biomedical companies, and legal firms. The campaign potentially exposes transaction data, travel history, and pattern-of-life analysis data from compromised systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between mobile app servers and critical financial systems through identity-based policy enforcement
- • Deploy Egress Security & Policy Enforcement to block unauthorized MQTT communications and detect data exfiltration attempts to external C2 domains
- • Enable Multicloud Visibility & Control to identify anomalous MQTT traffic patterns and suspicious automation targeting legitimate PKI software
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal Tendyron OnKey software behavior and alert on DLL sideloading attempts
- • Establish East-West Traffic Security controls to monitor and restrict workload-to-workload communications across compromised router infrastructure



