Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers
ID: d979ef4b-4189-5266-808d-25500b13fb1e
STIX ID: report--d979ef4b-4189-5266-808d-25500b13fb1e
Feed Name: Google Cloud Threat Intelligence
Threat Score
Mandiant discovered that UNC3886 deployed custom backdoors (TINYSHELL/lmpad variants) on Juniper Junos OS routers in mid-2024, using credential access to management infrastructure and a veriexec bypass via process injection (CVE-2025-21590) to achieve root access on end-of-life Juniper MX devices; the report covers malware analysis, TTPs, attribution, and recommends upgrading Juniper images and running the Juniper Malware Removal Tool (JMRT) scans.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
