• News/
  • https://www.bleepingcomputer.com/news/security/chinese-cyberspies-backdoor-juniper-routers-for-stealthy-access/

Chinese cyberspies backdoor Juniper routers for stealthy access

BleepingComputer
·
Bill Toulas
·
Published Mar 12, 2025
·
Updated

Chinese hackers are deploying custom backdoors on Juniper Networks Junos OS MX routers that have reached end-of-life (EoL) and no longer receive security updates. The backdoors are primarily variants of the TinyShell malware, an open-source tool that facilitates data exchange and command execution on Linux systems, and which has been used by multiple threat groups over the years. The attacks were discovered in mid-2024 by Mandiant, who attributed the attacks to a cyberespionage threat actor known as UNC3886. "In mid 2024, Mandiant discovered threat actors deployed custom backdoors operating on Juniper Networks' Junos OS routers," explains a new report by Mandiant. "Mandiant attributed these backdoors to the China-nexus espionage group, UNC3886. Mandiant uncovered several TINYSHELL based backdoors operating on Juniper Networks' Junos OS routers." This threat actor is known for sophisticated attacks utilizing zero-day vulnerabilities to compromise virtualization platforms and edge networking devices. In 2023, Chinese hackers were behind a series of attacks on government organizations using a Fortinet zero-day vulnerability (CVE-2022-41328) to deploy custom backdoors. Later that year, the threat actors exploited a VMware ESXi zero-day vulnerability to backdoor ESXi hosts. Mandiant has observed UNC3886 attacks starting from terminal servers used for managing network devices, where the threat actors used compromised credentials to access the Junos OS CLI and escalate to FreeBSD s...

Read full article

Affected Software

3 affected components
Juniper Networks Junos OS
Juniper Networks MX routers
Juniper Networks Junos OS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Chinese cyberspies deploying backdoors on Juniper Networks routers to maintain stealthy access.

2

What security implications are discussed in the article?

The article highlights the risks posed by outdated Juniper routers that no longer receive security updates, making them vulnerable to exploitation.

3

What products or software are affected by the reported backdoors?

The affected products include Juniper Networks' Junos OS and MX routers that have reached end-of-life.

4

What type of malware is mentioned in the article?

The article mentions variants of the TinyShell malware being used by the attackers.

5

Why is it concerning that the routers have reached end-of-life?

Routers that have reached end-of-life do not receive security updates, increasing their risk of being compromised and exploited by attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203