Cybersecurity experts have revealed information about a multi-platform cyberattack that employs the MQTT protocol for communication This article explores platform cyberattack employs. . The attack targets Windows and Linux systems.
The newly identified malware strain, dubbed BambooToken, has been operational since February 2023 and has been utilized in cyberattacks against businesses in Asia and South America. Black Lotus Labs revealed the previously unreported malware on VirusTotal in early 2026, with evidence indicating a sophisticated threat actor that has evaded detection thus far. While neither Tendyron's code-signing certificate nor its build environment has been compromised, it's suspected that the operators are relying on binary that's vulnerable to DLL sideloading to trigger attacks within targeted networks that likely have the program installed.
Specifically, the Mustang Panda group, known for their cyber activities, was observed using a backdoor called MQsTTang, which leverages IoT messaging protocols to execute commands on compromised hosts. This plugin uses the Windows Management Instrumentation (WMI) framework to gather details about installed antivirus products on the machine and exfiltrate them to the C2 server at "api80.c2iznja.com." Black Lotus Labs revealed that Cloudflare utilized the domains as a proxy for their infrastructure.
Although there is no proof of any overlap in the threat activity clusters, Lumen suggests that the threat actor might have adopted the Mustang Panda playbook to update its malware to support MQTT in upcoming versions.











