The banana stand: brokering and managing infections across Asia using MQTT
BambooToken is an emerging multiplatform malware family active since at least February 2023, utilizing the Message Queueing and Telemetry Transport (MQTT) protocol for covert command and control operations. The campaign targets Windows and Linux systems across Asia and South America, with infections observed on backend servers for mobile applications, legal and financial services, software companies, hotels, and GitLab instances. The malware leverages sideloading techniques through Tendyron's OnKey authentication software, commonly used in Chinese banking and government networks. Analysis reveals extensive host enumeration capabilities, plugins for antivirus detection, and potential keylogging and clipboard theft functions. Infrastructure analysis shows C2 domains ranking in Cloudflare's top 500,000, indicating widespread infections. The actor demonstrates sophisticated operational security, using MQTT's publish-subscribe architecture to hide infrastructure and employing Cloudflare proxies for additional o...
AI Analysis
Technical Summary
BambooToken is an emerging malware family active since early 2023 that leverages the MQTT protocol for command and control operations, enabling covert communication through a publish-subscribe architecture. It targets both Windows and Linux systems, focusing on backend servers in diverse industries across Asia and South America. The malware uses sideloading techniques involving Tendyron's OnKey authentication software, which is widely deployed in Chinese banking and government environments. Analysis shows BambooToken includes extensive host enumeration features, plugins to detect antivirus software, and capabilities for keylogging and clipboard data theft. Its command and control infrastructure is obscured using Cloudflare proxies, with C2 domains ranking within Cloudflare's top 500,000, indicating widespread infection. The actor demonstrates sophisticated operational security to evade detection and maintain persistence.
Potential Impact
The malware compromises backend servers in critical sectors such as finance, legal, software development, and hospitality, potentially enabling data theft, espionage, and persistent unauthorized access. Its capabilities include host reconnaissance, antivirus evasion, keylogging, and clipboard theft, which can lead to credential compromise and sensitive data exposure. The use of MQTT for C2 and Cloudflare proxies complicates detection and mitigation efforts. The infection across multiple countries in Asia and South America suggests a broad operational scope with potential regional impact on targeted organizations.
Mitigation Recommendations
No specific patch or remediation is indicated for this malware family. Organizations should focus on detecting and blocking the use of unauthorized sideloading of Tendyron's OnKey authentication software and monitor for unusual MQTT traffic patterns. Network defenses should consider the possibility of MQTT-based covert channels and Cloudflare proxy usage. Incident response should include host enumeration for signs of BambooToken infection and removal of compromised components. Since this is malware rather than a software vulnerability, no official patch exists. Continuous monitoring and threat intelligence updates are recommended.
Indicators of Compromise
- domain: chat5188.tk
- domain: api80.c2iznja.com
- ip: 210.1.231.13
- domain: base64.c2iznja.com
- domain: live-hk.c2iznja.com
- domain: newdma.c2iznja.com
- domain: turbo.c2iznja.com
- domain: api06.chat5188.tk
- domain: api08.chat5188.tk
- domain: apis.chat5188.tk
- domain: beacon.chat5188.tk
- domain: c2iznja.com
- domain: cache.c2iznja.com
- domain: ccc80.c2iznja.com
- domain: chat.chat5188.tk
- hash: b4cff5f5c6088d54df434d628d2e8e57
- hash: f36997eda793e037f215295c0ec2aa9f
- hash: 73ef71b97586e6490ef3b37e37b9abf0e3e19c2d
- hash: bed2b7acb36e01bf82e8a82e3e163e5cce9b395a
- hash: 07a2e365508fe05e8bc822fbeac14999ed535e0384be59343498c031dfa00d68
- hash: 1acc9b2f3bde5b3a3613feb59b03aae76197ad1e7d64d2a6fd4ce13cc3631e90
- hash: 1f01aa693602179651441b067b980f0ecf014328572e1b24893e00a97bacccd8
- hash: 257012d4a268d8552d98bba9ecc2b879df9b064a2fe5d3ff3677cef59af945c2
- hash: 2cbb7b04107eeab0fabb4f523f564acc69f1e8185f49542a88bec4f283ebdb71
- hash: 329f06012bca465dcaf1edbfdc20f1209b8ea00f269a8b890f165fb8c82c32d6
- hash: 44e3580d84ba7534e815ae9c12c4165fbc9313adc7475808908fec26e9b17f19
- hash: 50b743ffa29cf8fe6cc5f40acdd3a503a1a4e8f3dadaf7826b03112afeea9508
- hash: 5d06c1b06b48e9f61fec86179f194e0f611d6cf7495e0370a58844f0dddb437d
- hash: 5db0cb4167fa241c2377d24916c345c670ed096c09d9a9e09197d176674f4eb1
- hash: 661029691b45783502d554e63124da38cfe33cf3611381851da1562c66e3cfa6
- hash: 6663b63f70ceaee21a7cbff4bdfbe2916fa54759e839d76ba6d2372bcdb676d6
- hash: 75631b023b8fbbd7d69f7ce2353ef5559dea13b01a14aa5354d87549abf098f0
- hash: 96e0517d247e80b65bbafd9c4eee536676e4134e1f3b4aebe0cad53f9306a0ea
- hash: a0ca9f37352673fa3013f7cabd07dedd95b3237e1587ca43988a223c76d8e783
- hash: b5a2b06772a0362fb2c2defd63a1d892f3f80d93418b4dee99d655cc3da8581d
- hash: bf0681e43f51e98fe7ec24bf73a43facc66b0feb325a3a835f8f01b2861b926e
- hash: c4d4f8ccc9d2c4d289d8672396fdf0818b81551376057d43e76de66e29d73604
- hash: c6a1c0a8181b8388dd425fc18aad397cc6acd2e16a238e7713dd1656c88fe64e
- hash: ca024caa58c1da0259157399c9f76d797b0148708628051ffdd465d5ff0feead
- hash: caec31e6439085bbe187a5daf19ccb5e17aab29fa113461bf0433f99c9342c7d
- hash: ce4ce009fcebacf0b7e253409f1b192081b77f4d56bb3af0fa71d125aa060c51
- hash: d450e2fadbf20c8283b7cb0e1b54820c4a0a1d3dbb45ca895ac583d27189c53e
- hash: dffa94a0f9c4dc38d475a32741f7f134cc934c7b98bec581c135da1b5aa1983f
- hash: f8b8546daf5268e20e2ef7fe69c4442669c183c5c2b152bb11b23ad62ebcbd81
- hash: f8d57ed725f95f7784564a1bb1f5d9f7c3f6fc025ccc520188bccee0efd86a36
- hash: f6fe3856ba8c5e393a03575d2c1ca2e71e1cdbbb2d179c87e5da00d8ba7a24ef
- url: http://api80.c2iznja.com/Windows_Defender/Malwarebytes/
- domain: icanihazip.com
The banana stand: brokering and managing infections across Asia using MQTT
Description
BambooToken is an emerging multiplatform malware family active since at least February 2023, utilizing the Message Queueing and Telemetry Transport (MQTT) protocol for covert command and control operations. The campaign targets Windows and Linux systems across Asia and South America, with infections observed on backend servers for mobile applications, legal and financial services, software companies, hotels, and GitLab instances. The malware leverages sideloading techniques through Tendyron's OnKey authentication software, commonly used in Chinese banking and government networks. Analysis reveals extensive host enumeration capabilities, plugins for antivirus detection, and potential keylogging and clipboard theft functions. Infrastructure analysis shows C2 domains ranking in Cloudflare's top 500,000, indicating widespread infections. The actor demonstrates sophisticated operational security, using MQTT's publish-subscribe architecture to hide infrastructure and employing Cloudflare proxies for additional o...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
BambooToken is an emerging malware family active since early 2023 that leverages the MQTT protocol for command and control operations, enabling covert communication through a publish-subscribe architecture. It targets both Windows and Linux systems, focusing on backend servers in diverse industries across Asia and South America. The malware uses sideloading techniques involving Tendyron's OnKey authentication software, which is widely deployed in Chinese banking and government environments. Analysis shows BambooToken includes extensive host enumeration features, plugins to detect antivirus software, and capabilities for keylogging and clipboard data theft. Its command and control infrastructure is obscured using Cloudflare proxies, with C2 domains ranking within Cloudflare's top 500,000, indicating widespread infection. The actor demonstrates sophisticated operational security to evade detection and maintain persistence.
Potential Impact
The malware compromises backend servers in critical sectors such as finance, legal, software development, and hospitality, potentially enabling data theft, espionage, and persistent unauthorized access. Its capabilities include host reconnaissance, antivirus evasion, keylogging, and clipboard theft, which can lead to credential compromise and sensitive data exposure. The use of MQTT for C2 and Cloudflare proxies complicates detection and mitigation efforts. The infection across multiple countries in Asia and South America suggests a broad operational scope with potential regional impact on targeted organizations.
Defensive Guidance
No specific patch or remediation is indicated for this malware family. Organizations should focus on detecting and blocking the use of unauthorized sideloading of Tendyron's OnKey authentication software and monitor for unusual MQTT traffic patterns. Network defenses should consider the possibility of MQTT-based covert channels and Cloudflare proxy usage. Incident response should include host enumeration for signs of BambooToken infection and removal of compromised components. Since this is malware rather than a software vulnerability, no official patch exists. Continuous monitoring and threat intelligence updates are recommended.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.lumen.com/blog/en-us/the-banana-stand-brokering-and-managing-infections-across-asia-using-mqtt"]
- Pulse Id
- 6aaa65422d840de7e08ecf44
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainchat5188.tk | — | |
domainapi80.c2iznja.com | — | |
domainbase64.c2iznja.com | — | |
domainlive-hk.c2iznja.com | — | |
domainnewdma.c2iznja.com | — | |
domainturbo.c2iznja.com | — | |
domainapi06.chat5188.tk | — | |
domainapi08.chat5188.tk | — | |
domainapis.chat5188.tk | — | |
domainbeacon.chat5188.tk | — | |
domainc2iznja.com | — | |
domaincache.c2iznja.com | — | |
domainccc80.c2iznja.com | — | |
domainchat.chat5188.tk | — | |
domainicanihazip.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip210.1.231.13 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashb4cff5f5c6088d54df434d628d2e8e57 | — | |
hashf36997eda793e037f215295c0ec2aa9f | — | |
hash73ef71b97586e6490ef3b37e37b9abf0e3e19c2d | — | |
hashbed2b7acb36e01bf82e8a82e3e163e5cce9b395a | — | |
hash07a2e365508fe05e8bc822fbeac14999ed535e0384be59343498c031dfa00d68 | — | |
hash1acc9b2f3bde5b3a3613feb59b03aae76197ad1e7d64d2a6fd4ce13cc3631e90 | — | |
hash1f01aa693602179651441b067b980f0ecf014328572e1b24893e00a97bacccd8 | — | |
hash257012d4a268d8552d98bba9ecc2b879df9b064a2fe5d3ff3677cef59af945c2 | — | |
hash2cbb7b04107eeab0fabb4f523f564acc69f1e8185f49542a88bec4f283ebdb71 | — | |
hash329f06012bca465dcaf1edbfdc20f1209b8ea00f269a8b890f165fb8c82c32d6 | — | |
hash44e3580d84ba7534e815ae9c12c4165fbc9313adc7475808908fec26e9b17f19 | — | |
hash50b743ffa29cf8fe6cc5f40acdd3a503a1a4e8f3dadaf7826b03112afeea9508 | — | |
hash5d06c1b06b48e9f61fec86179f194e0f611d6cf7495e0370a58844f0dddb437d | — | |
hash5db0cb4167fa241c2377d24916c345c670ed096c09d9a9e09197d176674f4eb1 | — | |
hash661029691b45783502d554e63124da38cfe33cf3611381851da1562c66e3cfa6 | — | |
hash6663b63f70ceaee21a7cbff4bdfbe2916fa54759e839d76ba6d2372bcdb676d6 | — | |
hash75631b023b8fbbd7d69f7ce2353ef5559dea13b01a14aa5354d87549abf098f0 | — | |
hash96e0517d247e80b65bbafd9c4eee536676e4134e1f3b4aebe0cad53f9306a0ea | — | |
hasha0ca9f37352673fa3013f7cabd07dedd95b3237e1587ca43988a223c76d8e783 | — | |
hashb5a2b06772a0362fb2c2defd63a1d892f3f80d93418b4dee99d655cc3da8581d | — | |
hashbf0681e43f51e98fe7ec24bf73a43facc66b0feb325a3a835f8f01b2861b926e | — | |
hashc4d4f8ccc9d2c4d289d8672396fdf0818b81551376057d43e76de66e29d73604 | — | |
hashc6a1c0a8181b8388dd425fc18aad397cc6acd2e16a238e7713dd1656c88fe64e | — | |
hashca024caa58c1da0259157399c9f76d797b0148708628051ffdd465d5ff0feead | — | |
hashcaec31e6439085bbe187a5daf19ccb5e17aab29fa113461bf0433f99c9342c7d | — | |
hashce4ce009fcebacf0b7e253409f1b192081b77f4d56bb3af0fa71d125aa060c51 | — | |
hashd450e2fadbf20c8283b7cb0e1b54820c4a0a1d3dbb45ca895ac583d27189c53e | — | |
hashdffa94a0f9c4dc38d475a32741f7f134cc934c7b98bec581c135da1b5aa1983f | — | |
hashf8b8546daf5268e20e2ef7fe69c4442669c183c5c2b152bb11b23ad62ebcbd81 | — | |
hashf8d57ed725f95f7784564a1bb1f5d9f7c3f6fc025ccc520188bccee0efd86a36 | — | |
hashf6fe3856ba8c5e393a03575d2c1ca2e71e1cdbbb2d179c87e5da00d8ba7a24ef | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://api80.c2iznja.com/Windows_Defender/Malwarebytes/ | — |
Threat ID: 6aaa8c2b55bf5e2cf598affe
Added to database: 09/16/2026, 12:31:39 UTC
Last enriched: 09/16/2026, 12:48:25 UTC
Last updated: 09/17/2026, 04:26:47 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.