CuraSec

Plan active

BambooToken Malware Uses MQTT Protocol for Cross-Platform C2

2026-09-16 15:25 UTC · The Hacker News · read the source ↗ #malware#mqtt#c2
  • Engineer — Learn: MQTT-as-C2 is a novel evasion technique worth understanding when designing network egress controls — consider whether MQTT traffic on port 1883/8883 to external brokers is permitted in your environment. No KEV listing, PoC, or evidence of exploitation outside Asia/South America campaigns.
  • SOC/IR — Plan: MQTT is rarely monitored in enterprise SIEMs, making it an effective detection gap; add a hunt for unexpected outbound MQTT connections (ports 1883/8883) to external broker IPs as a low-cost coverage improvement this quarter. No IOCs were published in the disclosed research.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.