Black 'Magic' Targets Enterprise Juniper Routers With Backdoor
ID: 266cfedd-ab8b-5e68-887a-4a1d8a1a4ad0
STIX ID: report--266cfedd-ab8b-5e68-887a-4a1d8a1a4ad0
Feed Name: Dark Reading
A campaign named "J-magic" deploys a revived cd00r backdoor on Juniper enterprise routers (notably VPN gateways and devices with exposed NETCONF) that remains dormant until triggered by one of several highly specific "magic" TCP packets; upon validation via an encrypted challenge, the backdoor spawns a reverse shell to an attacker-controlled host, enabling data theft, configuration manipulation, and lateral movement. Infections have been observed since September 2023 with most cases in spring–summer 2024 across multiple countries and industries; the technique is stealthy because edge devices typically lack EDR and standard telemetry, creating a visibility blind spot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
