logo

Chinese cyberspies backdoor Juniper routers for stealthy access

ID: 03eb5b3f-357e-551a-b64f-b33cd0515c88

STIX ID: report--03eb5b3f-357e-551a-b64f-b33cd0515c88

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-03-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Mandiant discovered that UNC3886 (a China-linked espionage actor) deployed six TinyShell-derived backdoors on end-of-life Juniper MX routers in mid‑2024 by injecting malicious code into trusted processes to bypass Junos OS Veriexec protections; the backdoors provided remote shells, packet-sniffing, network-activated access, and logging disabling, with unique C2 methods and IoCs—Mandiant and Juniper recommend replacing unsupported devices, applying mitigations, and enforcing IAM/MFA, and published detection rules and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.