Someone is slipping a hidden backdoor into Juniper routers across the globe, activated by a magic packet
ID: 5748e911-a7b7-5ad4-8e2f-4247d37f0fec
STIX ID: report--5748e911-a7b7-5ad4-8e2f-4247d37f0fec
Feed Name: The Register (Security)
Black Lotus Labs discovered "J-Magic," an in-memory variant of the cd00r backdoor on Juniper Junos routers (many acting as VPN gateways) that passively monitors traffic using an eBPF filter and activates when one of five specially crafted "magic" packets is received; it then performs an RSA challenge and, if validated, establishes an SSL reverse shell giving full control of the device. Affected devices span multiple countries and critical sectors (semiconductors, energy, manufacturing); Black Lotus Labs published indicators of compromise and a research note with details: [The J‑Magic show — magic packets and where to find them](https://blog.lumen.com/the-j-magic-show-magic-packets-and-where-to-find-them/).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
