"The actor used Tendyron's 'OnKey' software to sideload agents into targeted machines," Lumen Black Lotus Labs said in a report shared with The Hacker News.
Lumen Black Lotus Labs discovery and timeline
Lumen Black Lotus Labs says it discovered a previously undocumented, multi-platform malware family codenamed BambooToken on VirusTotal in early 2026. The researchers assess the activity has been ongoing since at least February 2023 and that related activity was observed as recently as July 2026. The initial access vector that delivered BambooToken remains undetermined, the report said.
How BambooToken operates: MQTT for command-and-control and DLL sideloading
BambooToken uses the Message Queueing Telemetry Transport (MQTT) protocol — a lightweight publish-subscribe messaging standard — as its remote command-and-control (C2) channel. Early versions of the agent extracted a C2 server address from a .DAT file (or used a hard-coded fallback), collected system details, and reported to a server identified as "chat5188[.]tk". The C2 could then instruct the agent to load or stop plugins, terminate itself, or disconnect.
Later iterations sideload a rogue DLL named "OnKeyToken_KEB.dll" into the Tendyron OnKeySrv program to enumerate hosts and enter an MQTT-driven command loop. BambooToken also evolved from a PowerShell "stager" that allocated memory and ran a malicious file into a sideloading approach that Lumen said "would likely trigger fewer EDR alerts." As of December 2025, BambooToken expanded to target Linux hosts while continuing to rely on MQTT.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTies to Tendyron OnKey and the apparent attack surface
The malware leverages Tendyron's OnKey software — a second-generation PKI USB security token and authentication device used to protect online banking and financial transactions — by sideloading a rogue version of a DLL the legitimate program loads. On its website, Tendyron claims to have "190 million tokens in circulation." Lumen's analysis states that neither Tendyron's code-signing certificate nor its build environment has been compromised in connection with this activity; instead, the operators appear to be exploiting a binary vulnerable to DLL sideloading on machines where OnKey is installed.
Infrastructure, victims and geographic signals
Lumen reports that most BambooToken samples were uploaded to VirusTotal from Chinese IP space, suggesting a data-collection focus on users in China and neighboring countries. Researchers identified IP addresses geolocated to Singapore, Cambodia, and Vietnam communicating with an active C2 node; those IPs corresponded to MikroTik and DrayTek routers. Cloudflare was used as a proxy for the campaign infrastructure, and Lumen noted one domain associated with the 2025 campaign entered the top 500,000 domains on Cloudflare Radar, while an older domain ranked in the top 1 million at the peak of 2024 operations.
Lumen attributed a dozen compromised entities across Asia and South America, with most compromised servers associated with mobile applications. Specific victims named in the report include a GitLab server in Hong Kong, a Vietnamese company that develops a portable lifestyle-management device, a hotel in Vietnam, a biomedical company in Argentina, a legal firm in Chile, a cryptocurrency website in Lithuania, and a Malaysian finance organization.
Technical context: MQTT in the wild and related campaigns
The use of MQTT for C2 is not unique to BambooToken. Lumen notes similar MQTT-based tools and campaigns dating back to January 2023, including MQsTTang — a backdoor used by the Chinese nation-state hacking group Mustang Panda — as well as Android malware Tizi, the WailingCrab (aka WikiLoader) loader, and OT-focused IOCONTROL (aka OrpaCrab). Lumen observed that MQsTTang and BambooToken emerged around the same time in early 2023, and while it found no evidence of overlap, it said an actor could have taken inspiration from Mustang Panda to add MQTT support.
What this means for technologists, financial organizations, and mobile app owners
- Technologists and security teams: Expect to look for unusual MQTT traffic and signs of DLL sideloading tied to Tendyron's OnKeySrv process. Lumen highlighted a shift from PowerShell staging to DLL sideloading that may reduce EDR alerts, so defenders should instrument process loads and plugin activity for OnKeySrv and similar PKI token software.
- Financial organizations and Tendyron customers: Because the campaign specifically leverages OnKey binaries where present, organizations that deploy Tendyron tokens — including entities named on Tendyron's site — should review installations for rogue DLLs and validate build and load chains even though Lumen says no Tendyron signing keys or build systems have been shown to be compromised.
- Mobile app developers and service operators named as victims: Lumen's reporting links the majority of compromised servers to mobile applications. Operators of mobile back ends, device-management platforms, and related services should examine server logs for MQTT connections, Cloudflare-proxied domain patterns, and unexpected communications to domains like "api80.c2iznja[.]com" or "chat5188[.]tk".
Lumen concluded that using MQTT combined with Cloudflare routing "enables large-scale operation through an unconventional communication method" and that the campaign's targeting "supports extensive data collection" — from pattern-of-life data via mobile and wearable devices to potential exposure of financial transaction and hospitality travel records. The analysis also notes a SoftEther VPN connection from a VPS to a C2 node and says those and other signals "suggest a China nexus," though attribution remains unproven. The central unanswered technical question Lumen leaves on the table is how operators initially gain access to targeted systems — a detail that will shape defensive priorities going forward.




