# Researchers detail BambooToken malware's MQTT control channel

_Tuesday, September 15, 2026 at 11:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Researchers detail BambooToken malware's MQTT control channel — Primary](https://www.bleepstatic.com/content/hl-images/2024/03/05/hand.jpg)

Lumen's Black Lotus Labs reported that BambooToken malware has used MQTT for command-and-control communications with Windows and Linux systems. The framework, active since at least 2023, was observed compromising servers used by mobile apps, legal and financial services, and software development. MQTT lets infected machines receive commands through broker topics rather than direct attacker infrastructure. Lumen identified about a dozen compromised enterprise entities, but did not attribute the activity to a specific actor.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/)

---
Canonical: https://techandbusiness.org/newswire/wk-JTzXliqp6uW_8aRMIF2
Retrieved: 2026-09-15T19:09:43.883Z
Publisher: Tech & Business (techandbusiness.org)
