• News/
  • https://www.theregister.com/2025/01/25/mysterious_backdoor_juniper_routers/

Someone is slipping a hidden backdoor into Juniper routers across the globe, activated by a magic packet

The Register
·
Jessica Lyons
·
Published Jan 25, 2025
·
Updated

Someone has been quietly backdooring selected Juniper routers around the world in key sectors including semiconductor, energy, and manufacturing, since at least mid-2023. The devices were infected with what appears to be a variant of cd00r, a publicly available "invisible backdoor" designed to operate stealthily on a victim's machine by monitoring network traffic for specific conditions before activating. It's not yet publicly known how the snoops gained sufficient access to certain organizations' Junos OS equipment to plant the backdoor, which gives them remote control over the networking gear. What we do know is that about half of the devices have been configured as VPN gateways. Once injected, the backdoor, dubbed J-magic by Black Lotus Labs this week, resides in memory only and passively waits for one of five possible network packets to arrive. When one of those magic packet sequences is received by the machine, a connection is established with the sender, and a followup challenge is initiated by the backdoor. If the sender passes the test, they get command-line access to the box to commandeer it. As Black Lotus Labs explained in this research note on Thursday: "Once that challenge is complete, J-Magic establishes a reverse shell on the local file system, allowing the operators to control the device, steal data, or deploy malicious software." While it's not the first-ever discovered magic packet [PDF] malware, the team wrote, "the combination of targeting Junos OS routers...

Read full article

Affected Software

2 affected components
Juniper Junos OS
Juniper Junos OS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a hidden backdoor being inserted into Juniper routers globally, impacting critical sectors.

2

What security implications are discussed in the article?

The presence of a backdoor in Juniper routers poses significant risks to network security and data integrity.

3

What products or software are affected by the backdoor?

The backdoor specifically affects Juniper's Junos OS used in routers.

4

Who is likely targeted by this backdoor attack?

Key sectors such as semiconductor, energy, and manufacturing are likely the targets of this backdoor attack.

5

Since when has this backdoor been active according to the article?

The backdoor has been active since at least mid-2023.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203