MQsTTang is a custom Windows backdoor active since at least January 2023. It provides a minimal remote shell, executing attacker-supplied commands and returning standard output over MQTT-based command-and-control communications. The malware uses a legitimate public MQTT broker and the QMQTT library with statically linked Qt components, obscuring the operators’ backend infrastructure behind a publish/subscribe service. Later variants introduced debugger and monitoring-tool checks and modify their communications behavior when analysis is detected. MQsTTang copies itself to a public user location and establishes autorun persistence. It has been distributed in archive files containing a single executable masquerading as diplomatic, passport, and foreign-affairs material, consistent with spearphishing. Victim telemetry and lures indicate targeting of political and governmental organizations in Europe and Asia, including a governmental institution in Taiwan. The malware was initially attributed to Mustang Panda; as of July 2025, ESET attributes it to CeranaKeeper based on operational and TTP alignment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mustang Panda was observed in January 2023 using the MQsTTang backdoor, which uses MQTT to receive and execute commands on compromised hosts.
ESET researchers have analyzed MQsTTang, a new custom backdoor... MQsTTang is a barebones backdoor that allows the attacker to execute arbitrary commands on a victim’s machine and get the output... its use of the MQTT protocol for C&C communication.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The backdoor ... are executables with names related to foreign affairs, such as PDF_ Contacts List Of Invitated Deplomatic Members and Note_Documents_No.14-Tokyo-__From___Embassy___of___Russia_ . ... samples also contain folder icon in an attempt to deceive victims about their real purpose.
Similar to MQsTTang, the TinyNote backdoor samples also contain folder icon in an attempt to deceive victims about their real purpose.
“the registry key is created with the name qvlc. This matches the name of a legitimate executable used by VLC.”
“When creating copies, MQsTTang uses filenames of legitimate programs.”
BambooToken го користи протоколот Message Queuing Telemetry Transport (MQTT) како комуникациски канал за контрола на Windows и Linux системи... се влегува во команден циклус што користи MQTT за C2 комуникација.
The malware samples also communicate with other known C&C servers... constructs a GET request: http://5.188.33.190/api.php ... The encoded enumeration data is stored in a cookie called SSN ... expected result ... JSON ... {"msg":"[BASE64-ENCODED COMMAND]"}
This backdoor is unique because it communicates to its C&C servers over the MQTT protocol
“MQsTTang uses a legitimate public MQTT broker… broker.emqx.io”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mustang Panda backdoor that uses MQTT/IoT messaging infrastructure for command-and-control and execution of commands on compromised systems.
An unrelated backdoor mentioned solely as a prior example of malware using MQTT; no further capabilities or campaign details are provided.
A custom backdoor used by Mustang Panda for espionage and persistent access.
A backdoor noted as another example of malware using MQTT for command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.