JunOS and RedPenguin
ID: 9253b4b4-8670-51d7-a6d9-f6e51dc875cc
STIX ID: report--9253b4b4-8670-51d7-a6d9-f6e51dc875cc
Feed Name: Censys Blog
Date Published: 2025-03-14
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; The Censys Research Team
Censys describes the RedPenguin campaign that compromised Juniper MX routers (discovered July 2024) where attackers installed multiple daemons including a UDP-based RAT ('jdosd') and modified TinySHell backdoors with hard-coded C2 IPs; the report lists eight C2 addresses, analyzes those hosts (many showing ASUS router interfaces likely used as proxies), and highlights stealthy UDP C2 techniques (listener on UDP/33512) and forensic challenges in detecting this activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
