MalwareBambooToken Uses MQTT to Control Compromised Windows and Linux Systems
BambooToken malware uses MQTT brokers to control Windows and Linux hosts, enabling stealthy commands, data collection and modular plugins.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
MalwareBambooToken malware uses MQTT brokers to control Windows and Linux hosts, enabling stealthy commands, data collection and modular plugins.
APTChina-linked UTA0560 and APT31 chained Chrome and Windows zero-days via spear-phishing to breach NGOs, deploying GRIMWEDGE and credential-stealing malware.
APTRussian-linked actors exploit CVE-2026-20079 and CVE-2026-20316 in Cisco FMC to deploy redesigned Cyclops Blink backdoor for persistence and espionage.
MalwareHackers hijacked HBO Max's verified Reddit account to post 108 ClickFix ads targeting Windows and macOS users with credential stealers and crypto malware.
APTChina-linked Red Heron exploited CVE-2026-60004 Gitea RCE to breach 13 orgs, steal repos, harvest credentials and gain root access to internal networks.
RansomwareKaspersky links pro-Ukraine Hacking Cat to Gorilla RAT tunneling, Monkey ransomware and Nemo Wiper attacks on Russian targets since 2024.
MalwareTwitch Enhanced Viewer extension sent users' OAuth tokens to JeetBot proxies, exposing nearly 31,000 Chrome and Firefox users to account takeover.
APTNSA to replace directorates with five mission centers on China, cybersecurity, AI, combat support and global intelligence by January.
RansomwareUkrainian Conti ransomware operator Oleksii Lytvynenko sentenced to four years in US prison for hacking 12 firms and extortion.
APTUNC3569 exploited Sogou Input Method's sgbiz protocol and outdated Chromium browser to execute code and deploy GRAYRABBIT backdoor via DLL sideloading.
MalwareGoldFactory uses Gigabud and Vwork to clone Indonesian banking apps inside Android Work Profiles, evading fraud controls and causing $1M losses.
MalwareThousands of deceptive Android applications are abusing Google Play’s Early Access program to attract installs without exposing users to public reviews or