Chinese spies have for months exploited old Juniper Networks routers, infecting the buggy gear with custom backdoors and gaining root access to the compromised devices. According to a Tuesday report from Google Threat Intelligence and a Juniper Networks security advisory, the affected Juniper MX routers were running end-of-life hardware and software. Juniper issued a patch today to fix the issue. A "China-nexus" espionage group that Google and its Mandiant consulting biz track as UNC3886 has been exploiting a Junos OS vulnerability since at least mid-2024, but the attacks were not made public until now. Junos OS is Juniper Networks' operating system and powers most of the vendor's routing, switching, and security devices. It is based on a modified FreeBSD operating system. "Mandiant Consulting was working closely with the victim organization and Juniper Networks on this investigation and providing Juniper Networks time to create mitigation tools and patches," Austin Larsen, principal threat analyst at Google Threat Intelligence Group, told The Register. The threat intel group won't disclose the victim's sector or region, but noted that typically UNC3886 targets defense, technology, and telecommunication organizations located in the US and Asia. When asked how many routers were compromised in the victim's environment, Larsen said it was a "significant number of devices." Aside from maintaining a presence on the devices, Mandiant did not say what the snoops were hunting for in ...
Chinese snoops spotted on end-of-life Juniper routers
The Register
·Jessica Lyons
·Published Mar 12, 2025
·Updated
Affected Software
4 affected components
Juniper Networks MX routers
Juniper Networks Junos OS
Juniper Networks MX routers
Juniper Networks Junos OS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of outdated Juniper Networks routers by Chinese spies who have installed backdoors to gain root access.
2
What security implications are discussed?
The article highlights the risks associated with using end-of-life network equipment that can be easily compromised, leading to unauthorized access and potential data breaches.
3
What products or software are affected?
The affected products include Juniper Networks MX routers and the Junos OS software.
4
How long have the Chinese spies been exploiting these devices?
Chinese spies have reportedly exploited these outdated Juniper routers for several months.
5
What recommendations are given to mitigate this security issue?
The article suggests that organizations should avoid using end-of-life hardware and ensure their network equipment is regularly updated and patched.