This Linux Backdoor Hides Its Commands in Ordinary MQTT Traffic
BambooToken turns a protocol commonly used by sensors, appliances and small connected devices into a remote shell for Linux. Through an MQTT broker, an operator can collect host details, run commands, list directories and move files in both directions.
The reverse-engineering report covers one analysed sample. It does not establish how the malware was delivered, who operated it, which organisations were affected or whether the observed infrastructure remains active.
A broker separates the controller from the endpoint
At launch, the implant decodes a small embedded configuration to recover an MQTT broker and a fixed group topic. It creates a UUID-like client identifier, connects over TCP port 2883 and subscribes to group, client, shell, file and response topics. Failed connections are retried after 15 seconds.
Commands arrive as JSON and are passed to /bin/sh -c. Output is returned in chunks. The file worker can list directories, upload content to the victim, download files from it and delete regular files.
Transferred data uses a JSON header followed by a NUL byte and raw file content. A monitoring pipeline that expects every MQTT message to be valid JSON may parse the header and overlook the bytes that follow it.
The encoding is camouflage, not encryption
BambooToken applies a repeating XOR operation to payloads and topic labels. That can frustrate a quick text search, but it offers little protection once the key and protocol are understood. The misspelled directory-listing field flies, the fixed group topic and the NUL-delimited transfers provide more durable hunting pivots.
- Inventory legitimate MQTT brokers, clients and expected ports in server networks.
- Alert on Linux servers initiating unfamiliar MQTT sessions, especially over TCP 2883.
- Correlate those sessions with child
/bin/sh -cprocesses and unusual file access. - Inspect payloads beyond the first JSON object and account for binary data after a NUL separator.
- Search for the reported ELF hashes, fallback machine-ID path and encoded topic values.
- Restrict outbound MQTT from systems that do not need it.
Port 2883 alone is not evidence of compromise, and MQTT is not malicious. The useful detection is the combination of a new broker relationship, encoded command topics, shell creation and file movement from a host with no reason to behave like an IoT client.
Sources
- Reverser BambooToken analysis, published 21 September 2026.
- Cyber Security News technical summary, published 22 September 2026.


