National Cyber Warfare Foundation (NCWF)

Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration


0 user ratings
2026-09-22 10:49:40
milo
Red Team (CNA)

A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell commands, and transfer files through broker-mediated topics. Analysis of a statically linked x86-64 ELF sample shows that its configuration, task routing, and network payloads are obfuscated with separate XOR routines. The examined sample, SHA-256 […]


The post Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Mayura Kathir

Source: gbHackers
Source Link: https://gbhackers.com/linux-bambootoken-malware/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.