BlackTree Security · Infrastructure · Automation · AI

This Linux Backdoor Hides Its Commands in Ordinary MQTT Traffic

BambooToken turns a protocol commonly used by sensors, appliances and small connected devices into a remote shell for Linux. Through an MQTT broker, an operator can collect host details, run commands, list directories and move files in both directions.

The reverse-engineering report covers one analysed sample. It does not establish how the malware was delivered, who operated it, which organisations were affected or whether the observed infrastructure remains active.

A broker separates the controller from the endpoint

At launch, the implant decodes a small embedded configuration to recover an MQTT broker and a fixed group topic. It creates a UUID-like client identifier, connects over TCP port 2883 and subscribes to group, client, shell, file and response topics. Failed connections are retried after 15 seconds.

Commands arrive as JSON and are passed to /bin/sh -c. Output is returned in chunks. The file worker can list directories, upload content to the victim, download files from it and delete regular files.

Transferred data uses a JSON header followed by a NUL byte and raw file content. A monitoring pipeline that expects every MQTT message to be valid JSON may parse the header and overlook the bytes that follow it.

The encoding is camouflage, not encryption

BambooToken applies a repeating XOR operation to payloads and topic labels. That can frustrate a quick text search, but it offers little protection once the key and protocol are understood. The misspelled directory-listing field flies, the fixed group topic and the NUL-delimited transfers provide more durable hunting pivots.

  • Inventory legitimate MQTT brokers, clients and expected ports in server networks.
  • Alert on Linux servers initiating unfamiliar MQTT sessions, especially over TCP 2883.
  • Correlate those sessions with child /bin/sh -c processes and unusual file access.
  • Inspect payloads beyond the first JSON object and account for binary data after a NUL separator.
  • Search for the reported ELF hashes, fallback machine-ID path and encoded topic values.
  • Restrict outbound MQTT from systems that do not need it.

Port 2883 alone is not evidence of compromise, and MQTT is not malicious. The useful detection is the combination of a new broker relationship, encoded command topics, shell creation and file movement from a host with no reason to behave like an IoT client.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *