Chinese cyberspies backdoor Juniper routers for stealthy access
ID: 03eb5b3f-357e-551a-b64f-b33cd0515c88
STIX ID: report--03eb5b3f-357e-551a-b64f-b33cd0515c88
Feed Name: Bleeping Computer
Mandiant discovered that UNC3886 (a China-linked espionage actor) deployed six TinyShell-derived backdoors on end-of-life Juniper MX routers in mid‑2024 by injecting malicious code into trusted processes to bypass Junos OS Veriexec protections; the backdoors provided remote shells, packet-sniffing, network-activated access, and logging disabling, with unique C2 methods and IoCs—Mandiant and Juniper recommend replacing unsupported devices, applying mitigations, and enforcing IAM/MFA, and published detection rules and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
