Back to News
Cybersecurity

BambooToken Malware Leverages MQTT Protocol to Target Cross-Platform Systems

Researchers reveal BambooToken malware, which utilizes MQTT for controlling both Windows and Linux systems in targeted attacks.

Recent findings from cybersecurity researchers have unveiled a new multi-platform malware campaign known as BambooToken, which has been operational since at least February 2023. This malware employs the Message Queueing Telemetry Transport (MQTT) protocol as a unique communication channel to exert control over infected Windows and Linux systems. Initial assessments indicate that BambooToken has been actively used in cyberattacks against organizations primarily located in Asia and South America, raising concerns about its increasing prevalence and sophistication.

For businesses, the emergence of BambooToken underscores the necessity of enhancing cybersecurity measures, particularly for systems that utilize MQTT for IoT or cloud communications. The ability of this malware to target multiple operating systems means that enterprises must adopt a comprehensive security strategy, addressing vulnerabilities across diverse platforms. This development is particularly significant as it highlights the evolving tactics of cybercriminals, who are leveraging legitimate communication protocols to bypass traditional security defenses. As organizations continue to integrate AI and IoT solutions, understanding and mitigating the risks associated with such threats will be crucial for safeguarding sensitive data and maintaining operational integrity.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html)*