Plan
active
BambooToken Malware Uses MQTT Protocol for Cross-Platform C2
- Engineer — Learn: MQTT-as-C2 is a novel evasion technique worth understanding when designing network egress controls — consider whether MQTT traffic on port 1883/8883 to external brokers is permitted in your environment. No KEV listing, PoC, or evidence of exploitation outside Asia/South America campaigns.
- SOC/IR — Plan: MQTT is rarely monitored in enterprise SIEMs, making it an effective detection gap; add a hunt for unexpected outbound MQTT connections (ports 1883/8883) to external broker IPs as a low-cost coverage improvement this quarter. No IOCs were published in the disclosed research.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.