BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Summary

Cybersecurity researchers have identified a new multi-platform malware family, BambooToken, which has been active since at least February 2023. This malware utilizes the MQTT protocol to communicate and control both Windows and Linux systems, and has been observed in attacks targeting organizations in Asia and South America.

IFF Assessment

FOE

BambooToken is a new malware family that compromises and controls victim systems, posing a direct threat to defenders.

Defender Context

The emergence of BambooToken highlights the evolving tactics of threat actors in leveraging versatile protocols like MQTT for command and control across diverse operating systems. Defenders should monitor network traffic for unusual MQTT activity and ensure robust endpoint detection and response capabilities for both Windows and Linux environments to identify and mitigate such multi-platform threats.

Read Full Story →