Expired Juniper routers find new life – as Chinese spy hubs
ID: 5d2456d9-577a-5194-955f-ff1d171e30c2
STIX ID: report--5d2456d9-577a-5194-955f-ff1d171e30c2
Feed Name: The Register (Security)
This report details UNC3886 (a China-nexus espionage group) exploiting an end-of-life Junos OS flaw to compromise Juniper MX routers, deploying six modified TINYSHELL backdoors (appid, to, irad, Lmpad, jdosd, oemd) to maintain persistent, privileged access. Attackers gained access via terminal server credentials, used the shell and here-doc base64 techniques to drop binaries, and bypassed Junos Verified Exec by injecting malicious code into legitimate processes; Mandiant/Google investigated, Juniper released patches, and fewer than ten organizations are currently known to be affected, primarily in defense, technology, and telecom sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
