Chinese hackers are deploying custom backdoors on Juniper Networks Junos OS MX routers that have reached end-of-life (EoL) and no longer receive security updates. The backdoors are primarily variants of the TinyShell malware, an open-source tool that facilitates data exchange and command execution on Linux systems, and which has been used by multiple threat groups over the years. The attacks were discovered in mid-2024 by Mandiant, who attributed the attacks to a cyberespionage threat actor known as UNC3886. "In mid 2024, Mandiant discovered threat actors deployed custom backdoors operating on Juniper Networks' Junos OS routers," explains a new report by Mandiant. "Mandiant attributed these backdoors to the China-nexus espionage group, UNC3886. Mandiant uncovered several TINYSHELL based backdoors operating on Juniper Networks' Junos OS routers." This threat actor is known for sophisticated attacks utilizing zero-day vulnerabilities to compromise virtualization platforms and edge networking devices. In 2023, Chinese hackers were behind a series of attacks on government organizations using a Fortinet zero-day vulnerability (CVE-2022-41328) to deploy custom backdoors. Later that year, the threat actors exploited a VMware ESXi zero-day vulnerability to backdoor ESXi hosts. Mandiant has observed UNC3886 attacks starting from terminal servers used for managing network devices, where the threat actors used compromised credentials to access the Junos OS CLI and escalate to FreeBSD s...
Chinese cyberspies backdoor Juniper routers for stealthy access
BleepingComputer
·Bill Toulas
·Published Mar 12, 2025
·Updated
Affected Software
3 affected components
Juniper Networks Junos OS
Juniper Networks MX routers
Juniper Networks Junos OS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Chinese cyberspies deploying backdoors on Juniper Networks routers to maintain stealthy access.
2
What security implications are discussed in the article?
The article highlights the risks posed by outdated Juniper routers that no longer receive security updates, making them vulnerable to exploitation.
3
What products or software are affected by the reported backdoors?
The affected products include Juniper Networks' Junos OS and MX routers that have reached end-of-life.
4
What type of malware is mentioned in the article?
The article mentions variants of the TinyShell malware being used by the attackers.
5
Why is it concerning that the routers have reached end-of-life?
Routers that have reached end-of-life do not receive security updates, increasing their risk of being compromised and exploited by attackers.