Someone has been quietly backdooring selected Juniper routers around the world in key sectors including semiconductor, energy, and manufacturing, since at least mid-2023. The devices were infected with what appears to be a variant of cd00r, a publicly available "invisible backdoor" designed to operate stealthily on a victim's machine by monitoring network traffic for specific conditions before activating. It's not yet publicly known how the snoops gained sufficient access to certain organizations' Junos OS equipment to plant the backdoor, which gives them remote control over the networking gear. What we do know is that about half of the devices have been configured as VPN gateways. Once injected, the backdoor, dubbed J-magic by Black Lotus Labs this week, resides in memory only and passively waits for one of five possible network packets to arrive. When one of those magic packet sequences is received by the machine, a connection is established with the sender, and a followup challenge is initiated by the backdoor. If the sender passes the test, they get command-line access to the box to commandeer it. As Black Lotus Labs explained in this research note on Thursday: "Once that challenge is complete, J-Magic establishes a reverse shell on the local file system, allowing the operators to control the device, steal data, or deploy malicious software." While it's not the first-ever discovered magic packet [PDF] malware, the team wrote, "the combination of targeting Junos OS routers...
Someone is slipping a hidden backdoor into Juniper routers across the globe, activated by a magic packet
The Register
·Jessica Lyons
·Published Jan 25, 2025
·Updated
Affected Software
2 affected components
Juniper Junos OS
Juniper Junos OS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a hidden backdoor being inserted into Juniper routers globally, impacting critical sectors.
2
What security implications are discussed in the article?
The presence of a backdoor in Juniper routers poses significant risks to network security and data integrity.
3
What products or software are affected by the backdoor?
The backdoor specifically affects Juniper's Junos OS used in routers.
4
Who is likely targeted by this backdoor attack?
Key sectors such as semiconductor, energy, and manufacturing are likely the targets of this backdoor attack.
5
Since when has this backdoor been active according to the article?
The backdoor has been active since at least mid-2023.