A newly disclosed malware framework, codenamed BambooToken, communicates with compromised devices and issues control commands using the MQTT (Message Queuing Telemetry Transport) protocol. Researchers report the malware is active on both Windows and Linux systems, indicating a multi-platform capability for coordinating operations.

Both outlets describe BambooToken as an emerging threat with activity traced back to at least February 2023. The reports say the framework has been observed using MQTT as its communication channel, which can help it move commands and data between infected hosts and external infrastructure. One outlet additionally characterizes the campaign’s targeting as focused on organizations across Asia and South America.

While the outlets align on the malware’s core approach—MQTT-based communication and Windows/Linux control—the emphasis differs slightly: one focuses on the technical use of MQTT and the framework’s discovery, while the other highlights the assessed timeframe of operation and the regional scope of affected organizations.