logo

Someone is slipping a hidden backdoor into Juniper routers across the globe, activated by a magic packet

ID: 5748e911-a7b7-5ad4-8e2f-4247d37f0fec

STIX ID: report--5748e911-a7b7-5ad4-8e2f-4247d37f0fec

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2025-01-25

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Black Lotus Labs discovered "J-Magic," an in-memory variant of the cd00r backdoor on Juniper Junos routers (many acting as VPN gateways) that passively monitors traffic using an eBPF filter and activates when one of five specially crafted "magic" packets is received; it then performs an RSA challenge and, if validated, establishes an SSL reverse shell giving full control of the device. Affected devices span multiple countries and critical sectors (semiconductors, energy, manufacturing); Black Lotus Labs published indicators of compromise and a research note with details: [The J‑Magic show — magic packets and where to find them](https://blog.lumen.com/the-j-magic-show-magic-packets-and-where-to-find-them/).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.