Executive Summary

BambooToken is a sophisticated multi-platform malware campaign discovered in early 2026 that uses MQTT protocol for command and control across Windows and Linux systems. Active since February 2023, the threat actors exploit DLL sideloading techniques via Tendyron's OnKey authentication software to compromise organizations across Asia and South America. The malware demonstrates advanced evasion capabilities by leveraging legitimate PKI security tokens as attack vectors and using Cloudflare-proxied infrastructure to manage infections at scale. Researchers have identified compromised entities including mobile applications, financial organizations, hotels, and critical infrastructure systems across multiple countries.

This incident highlights the evolving sophistication of threat actors who are increasingly adopting unconventional communication protocols and supply chain attack vectors to evade traditional security controls and maintain persistent access to high-value targets.

Why This Matters Now

BambooToken represents a critical evolution in attack methodology, demonstrating how threat actors are weaponizing IoT protocols and legitimate security software to bypass modern detection systems while targeting critical infrastructure and financial institutions globally.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

BambooToken uses DLL sideloading via legitimate Tendyron OnKey software and MQTT protocol for command and control, making it difficult for traditional security tools to detect malicious activity.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have constrained BambooToken's lateral movement and C2 communications through network segmentation and egress controls. The blast radius across financial organizations and critical infrastructure would likely have been significantly reduced.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial malware deployment would likely face visibility constraints as CNSF monitoring could detect anomalous traffic patterns and unauthorized communication attempts from newly compromised endpoints

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Privilege escalation impact would likely be constrained through workload isolation policies that limit elevated process capabilities and restrict access to sensitive system resources even with compromised credentials

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-network propagation would likely be significantly constrained as east-west traffic controls could block unauthorized inter-segment communications and prevent access to critical financial systems and mobile application infrastructure

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communication channels would likely face detection and blocking as multicloud visibility could identify suspicious MQTT traffic patterns and unauthorized VPN connections to external infrastructure

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration scope would likely be reduced through controlled egress policies that restrict outbound data flows and limit unauthorized transmission of sensitive system information to external MQTT endpoints

Impact (Mitigations)

Overall campaign impact would likely be constrained to isolated network segments with reduced access to critical financial and biomedical systems, limiting the scope of intelligence gathering and pattern-of-life analysis capabilities

Impact at a Glance

Affected Business Functions

  • Financial Transaction Authentication
  • Secure Workstation Access
  • PKI Certificate Management
  • Mobile Application Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Extensive host information including system details, antivirus configurations, and authentication tokens from organizations across Asia and South America. Affected entities include mobile application companies, financial organizations, hospitality systems, biomedical companies, and legal firms. The campaign potentially exposes transaction data, travel history, and pattern-of-life analysis data from compromised systems.

Recommended Actions

  • Implement Zero Trust Segmentation to prevent lateral movement between mobile app servers and critical financial systems through identity-based policy enforcement
  • Deploy Egress Security & Policy Enforcement to block unauthorized MQTT communications and detect data exfiltration attempts to external C2 domains
  • Enable Multicloud Visibility & Control to identify anomalous MQTT traffic patterns and suspicious automation targeting legitimate PKI software
  • Activate Threat Detection & Anomaly Response capabilities to baseline normal Tendyron OnKey software behavior and alert on DLL sideloading attempts
  • Establish East-West Traffic Security controls to monitor and restrict workload-to-workload communications across compromised router infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image