By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers
Tech News

Custom Backdoor Exploiting Magic Packet Vulnerability in Juniper Routers

By Viral Trending Content 4 Min Read
Share
SHARE

Jan 23, 2025Ravie LakshmananMalware / Enterprise Security

Enterprise-grade Juniper Networks routers have become the target of a custom backdoor as part of a campaign dubbed J-magic.

According to the Black Lotus Labs team at Lumen Technologies, the activity is so named for the fact that the backdoor continuously monitors for a “magic packet” sent by the threat actor in TCP traffic.

“J-magic campaign marks the rare occasion of malware designed specifically for Junos OS, which serves a similar market but relies on a different operating system, a variant of FreeBSD,” the company said in a report shared with The Hacker News.

Cybersecurity

Evidence gathered by the company shows that the earliest sample of the backdoor dates back to September 2023, with the activity ongoing between mid-2023 and mid-2024. Semiconductor, energy, manufacturing, and information technology (IT) sectors were the most targeted.

Infections have been reported across Europe, Asia, and South America, including Argentine, Armenia, Brazil, Chile, Colombia, Indonesia, the Netherlands, Norway, Peru, the U.K., the U.S., and Venezuela.

The campaign is notable for deploying an agent after gaining initial access through an as-yet-undetermined method. The agent, a variant of a nearly 25-year-old, publicly available backdoor referred to as cd00r, waits for five different pre-defined parameters before commencing its operations.

On the receipt of these magic packets, the agent is configured to send back a secondary challenge, following which J-magic establishes a reverse shell to the IP address and port specified in the magic packet. This enables the attackers to control the device, steal data, or deploy additional payloads.

Lumen theorized that the inclusion of the challenge is an attempt on part of the adversary to prevent other threat actors from issuing magic packets in an indiscriminate manner and repurpose the J-magic agents to meet their own objectives.

It’s worth noting that another variant of cd00r, codenamed SEASPY, was deployed in connection with a campaign aimed at Barracuda Email Security Gateway (ESG) appliances in late 2022.

That said, there is no evidence at this stage to connect the two campaigns, nor does the J-magic campaign demonstrate any signs that it overlaps with other campaigns targeting enterprise-grade routers such as Jaguar Tooth and BlackTech (aka Canary Typhoon).

Cybersecurity

A majority of the potentially impacted IP addresses are said to be Juniper routers acting as VPN gateways, with a second smaller cluster comprising those with an exposed NETCONF port. It’s believed that the network configuration devices may have been targeted for their ability to automate router configuration information and management.

The exact end goals of the campaign are currently unknown, but the Black Lotus Labs team told The Hacker News that it saw “some interesting targeting” that aligned with the strategic goals for a certain country known for intellectual property theft, specifically aimed at the microprocessor manufacturing and shipbuilding verticals.

With routers being abused by nation-state actors preparing for follow-on attacks, the latest findings underscore the continued targeting of edge infrastructure, largely driven by the long uptime and a lack of endpoint detection and response (EDR) protections in such devices.

“One of the most notable aspects of the campaign is the focus on Juniper routers,” Lumen said. “While we have seen heavy targeting of other networking equipment, this campaign demonstrates that attackers can find success expanding to other device types such as enterprise grade routers.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

ServiceNow unveils AI Experience, the UI for enterprise AI

Sonnet 4.5 vs GLM 4.6 vs Codex : Detailed AI Coding Comparison

Top 3 leadership myths debunked

Adds Device Fingerprinting, PNG Steganography Payloads

Your Delivery Robot Is Here

TAGGED: Cyber Security, Cybersecurity, enterprise security, FreeBSD, Internet, IT security, Juniper Networks, JunoOS, Malware, Networking, Routers
Share This Article
Facebook Twitter Copy Link
Previous Article ‘We Send Bitcoin To Much Greater Heights,’ Trump Declares In Private
Next Article SEC wins in killing Kraken’s major questions doctrine defense
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Hamas willing to return remaining hostages in partial peace plan agreement; Trump orders stop to Gaza bombing
World News
Poland accuses Russia of attack plot involving explosives smuggled in corn tins
World News
Italians stage strike in support of Gaza Palestinians
World News
Commerce Minister Piyush Goyal drives investment reforms on Singapore visit
Business
XRP price outlook: why whales, ETFs, and rate cuts could send XRP soaring
Crypto
Silent Hill f: Why New Game+ (and Second, Third Runs) Are Essential
Gaming News
ServiceNow unveils AI Experience, the UI for enterprise AI
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Hamas willing to return remaining hostages in partial peace plan agreement; Trump orders stop to Gaza bombing

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Hamas willing to return remaining hostages in partial peace plan agreement; Trump orders stop to Gaza bombing
October 3, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?