Skip to main content

The banana stand: brokering and managing infections across Asia using MQTT

0
Medium
Published: 09/16/2026 (09/16/2026, 09:45:38 UTC)
Source: AlienVault OTX General

Description

BambooToken is an emerging multiplatform malware family active since at least February 2023, utilizing the Message Queueing and Telemetry Transport (MQTT) protocol for covert command and control operations. The campaign targets Windows and Linux systems across Asia and South America, with infections observed on backend servers for mobile applications, legal and financial services, software companies, hotels, and GitLab instances. The malware leverages sideloading techniques through Tendyron's OnKey authentication software, commonly used in Chinese banking and government networks. Analysis reveals extensive host enumeration capabilities, plugins for antivirus detection, and potential keylogging and clipboard theft functions. Infrastructure analysis shows C2 domains ranking in Cloudflare's top 500,000, indicating widespread infections. The actor demonstrates sophisticated operational security, using MQTT's publish-subscribe architecture to hide infrastructure and employing Cloudflare proxies for additional o...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/16/2026, 12:48:25 UTC

Technical Analysis

BambooToken is an emerging malware family active since early 2023 that leverages the MQTT protocol for command and control operations, enabling covert communication through a publish-subscribe architecture. It targets both Windows and Linux systems, focusing on backend servers in diverse industries across Asia and South America. The malware uses sideloading techniques involving Tendyron's OnKey authentication software, which is widely deployed in Chinese banking and government environments. Analysis shows BambooToken includes extensive host enumeration features, plugins to detect antivirus software, and capabilities for keylogging and clipboard data theft. Its command and control infrastructure is obscured using Cloudflare proxies, with C2 domains ranking within Cloudflare's top 500,000, indicating widespread infection. The actor demonstrates sophisticated operational security to evade detection and maintain persistence.

Potential Impact

The malware compromises backend servers in critical sectors such as finance, legal, software development, and hospitality, potentially enabling data theft, espionage, and persistent unauthorized access. Its capabilities include host reconnaissance, antivirus evasion, keylogging, and clipboard theft, which can lead to credential compromise and sensitive data exposure. The use of MQTT for C2 and Cloudflare proxies complicates detection and mitigation efforts. The infection across multiple countries in Asia and South America suggests a broad operational scope with potential regional impact on targeted organizations.

Defensive Guidance

No specific patch or remediation is indicated for this malware family. Organizations should focus on detecting and blocking the use of unauthorized sideloading of Tendyron's OnKey authentication software and monitor for unusual MQTT traffic patterns. Network defenses should consider the possibility of MQTT-based covert channels and Cloudflare proxy usage. Incident response should include host enumeration for signs of BambooToken infection and removal of compromised components. Since this is malware rather than a software vulnerability, no official patch exists. Continuous monitoring and threat intelligence updates are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.lumen.com/blog/en-us/the-banana-stand-brokering-and-managing-infections-across-asia-using-mqtt"]
Pulse Id
6aaa65422d840de7e08ecf44

Indicators of Compromise

Domain

ValueDescriptionCopy
domainchat5188.tk
domainapi80.c2iznja.com
domainbase64.c2iznja.com
domainlive-hk.c2iznja.com
domainnewdma.c2iznja.com
domainturbo.c2iznja.com
domainapi06.chat5188.tk
domainapi08.chat5188.tk
domainapis.chat5188.tk
domainbeacon.chat5188.tk
domainc2iznja.com
domaincache.c2iznja.com
domainccc80.c2iznja.com
domainchat.chat5188.tk
domainicanihazip.com

Ip

ValueDescriptionCopy
ip210.1.231.13

Hash

ValueDescriptionCopy
hashb4cff5f5c6088d54df434d628d2e8e57
hashf36997eda793e037f215295c0ec2aa9f
hash73ef71b97586e6490ef3b37e37b9abf0e3e19c2d
hashbed2b7acb36e01bf82e8a82e3e163e5cce9b395a
hash07a2e365508fe05e8bc822fbeac14999ed535e0384be59343498c031dfa00d68
hash1acc9b2f3bde5b3a3613feb59b03aae76197ad1e7d64d2a6fd4ce13cc3631e90
hash1f01aa693602179651441b067b980f0ecf014328572e1b24893e00a97bacccd8
hash257012d4a268d8552d98bba9ecc2b879df9b064a2fe5d3ff3677cef59af945c2
hash2cbb7b04107eeab0fabb4f523f564acc69f1e8185f49542a88bec4f283ebdb71
hash329f06012bca465dcaf1edbfdc20f1209b8ea00f269a8b890f165fb8c82c32d6
hash44e3580d84ba7534e815ae9c12c4165fbc9313adc7475808908fec26e9b17f19
hash50b743ffa29cf8fe6cc5f40acdd3a503a1a4e8f3dadaf7826b03112afeea9508
hash5d06c1b06b48e9f61fec86179f194e0f611d6cf7495e0370a58844f0dddb437d
hash5db0cb4167fa241c2377d24916c345c670ed096c09d9a9e09197d176674f4eb1
hash661029691b45783502d554e63124da38cfe33cf3611381851da1562c66e3cfa6
hash6663b63f70ceaee21a7cbff4bdfbe2916fa54759e839d76ba6d2372bcdb676d6
hash75631b023b8fbbd7d69f7ce2353ef5559dea13b01a14aa5354d87549abf098f0
hash96e0517d247e80b65bbafd9c4eee536676e4134e1f3b4aebe0cad53f9306a0ea
hasha0ca9f37352673fa3013f7cabd07dedd95b3237e1587ca43988a223c76d8e783
hashb5a2b06772a0362fb2c2defd63a1d892f3f80d93418b4dee99d655cc3da8581d
hashbf0681e43f51e98fe7ec24bf73a43facc66b0feb325a3a835f8f01b2861b926e
hashc4d4f8ccc9d2c4d289d8672396fdf0818b81551376057d43e76de66e29d73604
hashc6a1c0a8181b8388dd425fc18aad397cc6acd2e16a238e7713dd1656c88fe64e
hashca024caa58c1da0259157399c9f76d797b0148708628051ffdd465d5ff0feead
hashcaec31e6439085bbe187a5daf19ccb5e17aab29fa113461bf0433f99c9342c7d
hashce4ce009fcebacf0b7e253409f1b192081b77f4d56bb3af0fa71d125aa060c51
hashd450e2fadbf20c8283b7cb0e1b54820c4a0a1d3dbb45ca895ac583d27189c53e
hashdffa94a0f9c4dc38d475a32741f7f134cc934c7b98bec581c135da1b5aa1983f
hashf8b8546daf5268e20e2ef7fe69c4442669c183c5c2b152bb11b23ad62ebcbd81
hashf8d57ed725f95f7784564a1bb1f5d9f7c3f6fc025ccc520188bccee0efd86a36
hashf6fe3856ba8c5e393a03575d2c1ca2e71e1cdbbb2d179c87e5da00d8ba7a24ef

Url

ValueDescriptionCopy
urlhttp://api80.c2iznja.com/Windows_Defender/Malwarebytes/

Threat ID: 6aaa8c2b55bf5e2cf598affe

Added to database: 09/16/2026, 12:31:39 UTC

Last enriched: 09/16/2026, 12:48:25 UTC

Last updated: 09/17/2026, 04:26:47 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses