{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/bamboo-token/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["network-security","command-and-control","mqtt","bamboo-token","wailing-crab"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe MQTT (Message Queuing Telemetry Transport) protocol is increasingly utilized by threat actors for command and control (C2) communication due to its lightweight publish/subscribe architecture. Malware such as BambooToken, IOCONTROL, MQsTTang, and WailingCrab leverage MQTT to receive commands and exfiltrate data while masking traffic within typical IoT or application messaging flows. Attackers commonly target TCP ports 1883, 2883, and 8883 for these connections. Defenders can identify this activity by monitoring network telemetry for first-seen connections to external MQTT brokers.\u003c/p\u003e\n\u003cp\u003eDetection requires deep packet inspection (DPI) or protocol-aware security sensors to decode MQTT traffic. Without SSL/TLS decryption, encrypted sessions may only be classified generically as SSL/TLS, limiting visibility. Defenders should correlate these network connections with endpoint activity, specifically looking for unsigned binaries or persistence mechanisms such as BambooToken's associated files: OnKeySrv.exe, OnKeyToken_KEB.dll, and OnKeySrv.dat.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to establish persistent, stealthy C2 channels that bypass traditional direct-connect detection methods. The use of MQTT enables the deployment of modular plugins and the remote execution of commands, potentially leading to unauthorized data exfiltration, system manipulation, or further lateral movement within the network. Sectors relying heavily on IoT infrastructure are particularly vulnerable to this communication pattern.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement the provided detection logic to surface first-seen connections to external MQTT brokers using Suricata, Zeek, or PAN-OS logs.\u003c/li\u003e\n\u003cli\u003eReview all flagged connections to determine if the originating asset is an authorized MQTT client.\u003c/li\u003e\n\u003cli\u003eCorrelate network alerts with endpoint telemetry, specifically investigating unauthorized MQTT-capable processes, shell execution, or suspicious DLL loads (e.g., OnKeySrv.exe).\u003c/li\u003e\n\u003cli\u003eRestrict outbound MQTT traffic to verified broker addresses and ports (e.g., 1883, 2883, 8883) where operational requirements permit.\u003c/li\u003e\n\u003cli\u003eValidate that network sensors are positioned to observe traffic before Source NAT to ensure visibility into the originating internal IP.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T16:10:18Z","date_published":"2026-09-28T16:10:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mqtt-c2/","summary":"This brief describes the detection of anomalous MQTT traffic to external brokers, a communication channel leveraged by malware like BambooToken and WailingCrab for command and control.","title":"Detection of Unauthorized External MQTT Broker Connections","url":"https://feed.craftedsignal.io/briefs/2026-09-mqtt-c2/"}],"language":"en","title":"CraftedSignal Threat Feed - Bamboo-Token","version":"https://jsonfeed.org/version/1.1"}