logo

Black 'Magic' Targets Enterprise Juniper Routers With Backdoor

ID: 266cfedd-ab8b-5e68-887a-4a1d8a1a4ad0

STIX ID: report--266cfedd-ab8b-5e68-887a-4a1d8a1a4ad0

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-01-23

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A campaign named "J-magic" deploys a revived cd00r backdoor on Juniper enterprise routers (notably VPN gateways and devices with exposed NETCONF) that remains dormant until triggered by one of several highly specific "magic" TCP packets; upon validation via an encrypted challenge, the backdoor spawns a reverse shell to an attacker-controlled host, enabling data theft, configuration manipulation, and lateral movement. Infections have been observed since September 2023 with most cases in spring–summer 2024 across multiple countries and industries; the technique is stealthy because edge devices typically lack EDR and standard telemetry, creating a visibility blind spot.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.