MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-15 · via BleepingComputer

New malware framework uses MQTT for cross-platform command and control

Image via BleepingComputer
Image via BleepingComputer

A previously undocumented malware framework called BambooToken has been active since at least 2023 and now uses the MQTT messaging protocol to communicate with compromised Windows and Linux systems. The malware subscribes to broker topics tied to unique identifiers, allowing attackers to send commands and receive system information without direct connections to their infrastructure. Researchers found evidence of keylogging, clipboard theft, and other surveillance capabilities, though some of these were only present in dead code.

Expanded Detail

The BambooToken framework’s shift to MQTT marks a notable evolution in malware design, leveraging a protocol built for lightweight IoT messaging to create resilient, asynchronous command channels. By routing traffic through public brokers and topic-based identifiers, infected machines avoid direct contact with attacker servers, complicating network-based detection and takedown efforts. The campaign’s reach, observed across Asia and South America, includes hotels, law firms, biomedical companies, and a cryptocurrency site, with several compromised servers tied to mobile app backends. A GitLab breach in Hong Kong raises supply-chain concerns, while the targeting of SpeedCN VPN users suggests a focus on overseas Chinese audiences. The Linux variant, still under development, indicates ongoing refinement.

Context

This malware’s use of a mainstream IoT protocol could lower the barrier for other threat actors to adopt similar stealthy C2 methods, potentially making attacks harder for organizations to spot. Businesses relying on cloud or mobile infrastructure may face increased risk of silent data exfiltration, especially if they lack visibility into unusual broker traffic. The targeting of legal, financial, and biomedical sectors suggests sensitive data is at stake, which could erode trust in digital services if breaches become more frequent. However, the impact remains limited to specific regions and entities, and defenders can adapt by monitoring MQTT activity and hardening server environments.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Compromised HBO Max Reddit account used to spread info-stealing malware via fake ads · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “BambooToken malware controls Windows and Linux systems via MQTT.” Browse more stories.