logo

Stealthy 'Magic Packet' malware targets Juniper VPN gateways

ID: 7a9621b7-df07-55c1-aa84-d0be88079ba6

STIX ID: report--7a9621b7-df07-55c1-aa84-d0be88079ba6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-01-23

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

J-magic is a stealthy backdoor campaign targeting Juniper edge routers (often used as VPN gateways) that passively monitors TCP traffic using eBPF filters for a specially crafted "magic packet"; when the packet satisfies one of five conditions and correctly responds to an RSA challenge, the malware spawns a reverse shell. Black Lotus Labs observed the campaign across semiconductor, energy, manufacturing, and IT sectors between mid-2023 and mid-2024, noting the operator’s use of challenge-response and in-memory persistence to minimize detection and enable long-term access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.