The record
Written from the 1 report below. Nothing here is unsourced.
- A previously undocumented malware family called BambooToken uses the MQTT messaging protocol to control Windows and Linux systems.
- The malware is assessed to have been active since at least February 2023 and has targeted organizations across Asia and South America.
- Attackers sideload malicious code through Tendyron's OnKey software, a USB security token used for high-security authentication in sectors including China's financial and government industries.
- Lumen Black Lotus Labs says a dozen compromised entities have been detected, including a GitLab server in Hong Kong, a hotel in Vietnam, and a biomedical company in Argentina.
- The identity of the threat actor remains unknown, though technical details suggest a China nexus, and infected infrastructure was still active as recently as July 2026.
What to watch next
- Whether the initial access vector used to deliver BambooToken is identified.
- Whether BambooToken expands beyond Windows and Linux to additional platforms.
- Further findings on the threat actor's identity and any links to the Mustang Panda group.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Black Lotus Labs
threat research arm of Lumen Technologies
1 quote · 1 outlet
“The actor used Tendyron's 'OnKey' software to sideload agents into targeted machines”
In the article
…malware on VirusTotal in early 2026, with evidence pointing to a skilled threat actor that has managed to stay undetected until now. The initial access vector used to deliver BambooToken remains undetermined. " The actor used Tendyron's 'OnKey' software to sideload agents into targeted machines ," Black Lotus Labs said in a report shared with The Hacker News. "Tendyron creates hardware-based tokens employed in high-security settings to verify user identities for workstation access. Their website lists…
Ryan English
information security engineer
1 quote · 1 outlet
“The first version of BambooToken was initiated via a PowerShell script”
In the article
…the Tendyron OnKeySrv program to enumerate the host and enter into a command loop that uses MQTT for C2. As of December 2025, BambooToken has expanded in scope to also target Linux hosts while still relying on MQTT. " The first version of BambooToken was initiated via a PowerShell script ," Ryan English, information security engineer at Lumen Technologies Black Lotus Labs, told The Hacker News. "The PowerShell script would act as a 'stager' by allocating memory and then running the malicious file. We…
Coverage1
All filed from India
Named China · Singapore · Cambodia · Vietnam · Argentina · Chile · Lithuania · Malaysia · Israel · United States · Hong Kong SAR China · DrayTek · GitLab · MikroTik · Tendyron · Bamboo Spider · BambooToken · Black Lotus Labs · Cloudflare · IOCONTROL · Lumen Technologies · MQsTTang · Mustang Panda
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
