Stealthy 'Magic Packet' malware targets Juniper VPN gateways
ID: 7a9621b7-df07-55c1-aa84-d0be88079ba6
STIX ID: report--7a9621b7-df07-55c1-aa84-d0be88079ba6
Feed Name: Bleeping Computer
J-magic is a stealthy backdoor campaign targeting Juniper edge routers (often used as VPN gateways) that passively monitors TCP traffic using eBPF filters for a specially crafted "magic packet"; when the packet satisfies one of five conditions and correctly responds to an RSA challenge, the malware spawns a reverse shell. Black Lotus Labs observed the campaign across semiconductor, energy, manufacturing, and IT sectors between mid-2023 and mid-2024, noting the operator’s use of challenge-response and in-memory persistence to minimize detection and enable long-term access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
