China-Backed Hackers Backdoor US Carrier-Grade Juniper MX Routers
ID: 9d25f266-f18f-586d-91dd-762983bb9923
STIX ID: report--9d25f266-f18f-586d-91dd-762983bb9923
Feed Name: Dark Reading
Threat Score
Mandiant disclosed that UNC3886 (China-nexus) actively compromised Juniper MX routers—many running EOL Junos OS—by abusing terminal server credentials, deploying TinyShell backdoors, backdooring TACACS+, and evading Veriexec protections; Juniper released an advisory and patch for CVE-2025-21590 and customers are urged to upgrade, run the Juniper Malware Removal Tool, and improve authentication and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
