Stealthy “Magic Packet” Backdoor Discovered Targeting Critical Juniper Network Infrastructure

Stealthy

J-magic: New Backdoor Targeting Juniper Networks Routers

A sophisticated backdoor campaign dubbed “J-magic” has been discovered targeting enterprise-grade Juniper Networks routers. The Black Lotus Labs at Lumen Technologies revealed that this malware, specifically designed for Junos OS, monitors TCP traffic for specific “magic packets” sent by threat actors.

The campaign, active between mid-2023 and mid-2024, has primarily affected semiconductor, energy, manufacturing, and IT sectors across multiple continents. Affected regions include Europe, Asia, and South America, with infections reported in 12 countries including the U.S., U.K., and Brazil.

Technical Details:
– The backdoor is a variant of cd00r, a 25-year-old publicly available backdoor
– Requires five pre-defined parameters before activation
– Establishes a reverse shell upon receiving specific magic packets
– Implements a secondary challenge mechanism to prevent unauthorized access

The majority of compromised devices are Juniper routers functioning as VPN gateways, with some targeted devices exposing NETCONF ports for router configuration management. While similar to other router-targeting campaigns like Jaguar Tooth and BlackTech, J-magic appears to be a distinct operation.

The campaign highlights the growing vulnerability of edge infrastructure devices, which are particularly susceptible due to:
– Extended uptime periods
– Lack of endpoint detection and response (EDR) protection
– Critical position in network infrastructure

This unprecedented focus on Juniper routers demonstrates attackers’ ability to successfully expand their targets to various enterprise-grade network devices, presenting a significant security concern for organizations worldwide.

Share This Article