BambooToken's MQTT Command and Control Emerges
A sophisticated and previously unknown malware framework, dubbed BambooToken, has been identified actively compromising both Windows and Linux systems. What sets BambooToken apart is its novel use of the Message Queuing Telemetry Transport (MQTT) protocol for command and control (C2) communications. This lightweight messaging protocol, typically used for IoT devices and low-bandwidth environments, provides an unusual and stealthy channel for malware operators to issue commands and exfiltrate data. Security researchers have observed BambooToken's activity dating back to at least early 2023, indicating a sustained and evolving threat. The choice of MQTT is a significant departure from typical malware C2 methods, which often rely on HTTP, DNS tunneling, or custom TCP/UDP protocols. MQTT's publish-subscribe model allows for efficient, asynchronous messaging, making it difficult to distinguish malicious traffic from legitimate IoT device communication. This stealth capability is crucial for maintaining persistence and evading detection by network security monitoring tools.
