logo

Expired Juniper routers find new life – as Chinese spy hubs

ID: 5d2456d9-577a-5194-955f-ff1d171e30c2

STIX ID: report--5d2456d9-577a-5194-955f-ff1d171e30c2

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-03-12

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

This report details UNC3886 (a China-nexus espionage group) exploiting an end-of-life Junos OS flaw to compromise Juniper MX routers, deploying six modified TINYSHELL backdoors (appid, to, irad, Lmpad, jdosd, oemd) to maintain persistent, privileged access. Attackers gained access via terminal server credentials, used the shell and here-doc base64 techniques to drop binaries, and bypassed Junos Verified Exec by injecting malicious code into legitimate processes; Mandiant/Google investigated, Juniper released patches, and fewer than ten organizations are currently known to be affected, primarily in defense, technology, and telecom sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.