logo

China-Backed Hackers Backdoor US Carrier-Grade Juniper MX Routers

ID: 9d25f266-f18f-586d-91dd-762983bb9923

STIX ID: report--9d25f266-f18f-586d-91dd-762983bb9923

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-03-12

Date Updated: 2026-04-21

Author: Rob Wright

...
...

Mandiant disclosed that UNC3886 (China-nexus) actively compromised Juniper MX routers—many running EOL Junos OS—by abusing terminal server credentials, deploying TinyShell backdoors, backdooring TACACS+, and evading Veriexec protections; Juniper released an advisory and patch for CVE-2025-21590 and customers are urged to upgrade, run the Juniper Malware Removal Tool, and improve authentication and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.