Backdoor

Juniper Routers Exploited via Magic Packet Vulnerability to Deploy Custom Backdoor

A sophisticated cyber campaign dubbed “J-magic” has been discovered targeting enterprise-grade Juniper routers with a backdoor attack that leverages a passive monitoring agent.

The operation, first detected in September 2023, employs a variant of the cd00r backdoor that continuously scans for specific “magic packets” in TCP traffic.

Technical Implementation

The malware, masquerading as “JunoscriptService,” operates by establishing an eBPF filter on specified interfaces and ports.

Upon installation, it renames itself “[nfsiod 0]” to blend in with legitimate NFS processes.

The backdoor monitors incoming TCP traffic for five distinct predefined parameters, and when triggered by a matching “magic packet,” it initiates a secondary challenge before establishing a reverse shell.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

The campaign has primarily focused on organizations using Juniper routers as VPN gateways, with approximately 50% of targeted devices serving this function.

The attackers strategically targeted semiconductor, energy, manufacturing, and IT sectors, with victims spread across multiple countries.

The operation demonstrated particular interest in devices that could serve as network crossroads, potentially enabling deeper access into corporate networks.

According to the Lumen report, what sets J-magic apart is its sophisticated operational security measures.

The malware implements a unique RSA challenge mechanism, requiring attackers to correctly respond to a five-character random string encrypted with a hardcoded public key.

This feature appears designed to prevent unauthorized actors from hijacking compromised systems, showing an evolution in tradecraft compared to earlier variants.

The campaign remained active from mid-2023 through at least mid-2024, with telemetry indicating less than 0.01% of analyzed netflow corresponding to potential compromises across 36 unique IP addresses globally.

While sharing some technical indicators with the previously known SeaSpy2 malware family, researchers maintain low confidence in direct attribution due to limited technical overlap.

Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar

Aman Mishra

Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Recent Posts

GitVenom Campaign Abuses Thousands of GitHub Repositories to Infect Users

The GitVenom campaign, a sophisticated cyber threat, has been exploiting GitHub repositories to spread malware…

37 minutes ago

UAC-0212: Hackers Unleash Devastating Cyber Assault on Critical Infrastructure

In a recent escalation of cyber threats, hackers have launched a targeted campaign, identified as…

40 minutes ago

Widespread Chrome Malware: 16 Extensions Infect Over 3.2 Million Users

A recent cybersecurity investigation has uncovered a cluster of 16 malicious Chrome extensions that have…

41 minutes ago

Sliver C2 Server Vulnerability Enables TCP Hijacking for Traffic Interception

A significant vulnerability has been discovered in the Sliver C2 server, a popular open-source cross-platform…

45 minutes ago

TSforge New Tool Bypasses Windows Activation on All Versions

A significant breakthrough in bypassing Windows activation has been achieved with the introduction of TSforge,…

53 minutes ago

Cybercriminals Impersonate Windows “Commander Tool” to Launch LummaC2 Malware Attack

The AhnLab Security Intelligence Center (ASEC) has uncovered a new cyberattack campaign leveraging the LummaC2…

1 hour ago