BambooToken Malware Adopted MQTT for Command Operations
A newly identified Linux variant leverages standard messaging protocols to bypass traditional network inspection.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Do you feel confident that your connected devices are secure against remote hacking attempts?
Security researchers have identified a Linux-based variant of the BambooToken malware that utilizes the MQTT messaging protocol for command-and-control operations. This research-stage development enables attackers to perform host profiling, shell command execution, and file exfiltration through broker-mediated topics.
Why it matters
By adopting MQTT, a common messaging standard, for C2 infrastructure, the malware complicates detection efforts that rely on identifying anomalous non-standard traffic. This technique allows for stealthier communication channels in compromised environments by blending in with legitimate machine-to-machine traffic.
The analyzed sample is a statically linked x86-64 ELF file, utilizing XOR routines to obfuscate configuration, task routing, and network payloads. This architecture allows the malware to interact with MQTT brokers to exfiltrate files and execute remote shell commands.
The players
BambooToken
A modular malware strain known for its ability to profile hosts and exfiltrate sensitive files from infected systems.
The details
The malware operates by connecting to an MQTT broker—a server that distributes messages between clients—using specifically mediated topics to receive instructions. To protect its operational logic, the binary employs multiple distinct XOR routines—a simple logic-based data scrambling technique—to mask its internal configuration and communication payloads. This approach effectively hides the command structure within the data stream, making it harder for signature-based detection systems to intercept or interpret the malicious traffic.
Timeline
September 22, 2026: The security report regarding this Linux variant was published.
The Tech Race
The adoption of MQTT as a command-and-control channel follows a broader trend of malware operators pivoting toward ubiquitous IoT protocols to evade network monitoring. This development forces security vendors to evolve beyond simple IP-based blocking toward more granular, application-layer payload inspection.
Organizations running Linux-based environments should prioritize inspecting outbound MQTT traffic for unauthorized broker connections. Because this malware relies on obfuscated payloads, legacy perimeter defenses that do not perform deep packet inspection of message topics may fail to detect active communication.
The takeaway
The pivot to MQTT highlights that standard, legitimate infrastructure is increasingly being repurposed for malicious signaling. Security teams should monitor for unusual broker-mediated traffic patterns to identify potential BambooToken activity.
Further reading
For more information on emerging threat patterns, see our coverage in Cybersecurity.
Live Poll
Do you feel confident that your connected devices are secure against remote hacking attempts?






