• News/
  • https://www.theregister.com/2025/03/12/china_spy_juniper_routers/

Chinese snoops spotted on end-of-life Juniper routers

The Register
·
Jessica Lyons
·
Published Mar 12, 2025
·
Updated

Chinese spies have for months exploited old Juniper Networks routers, infecting the buggy gear with custom backdoors and gaining root access to the compromised devices. According to a Tuesday report from Google Threat Intelligence and a Juniper Networks security advisory, the affected Juniper MX routers were running end-of-life hardware and software. Juniper issued a patch today to fix the issue. A "China-nexus" espionage group that Google and its Mandiant consulting biz track as UNC3886 has been exploiting a Junos OS vulnerability since at least mid-2024, but the attacks were not made public until now. Junos OS is Juniper Networks' operating system and powers most of the vendor's routing, switching, and security devices. It is based on a modified FreeBSD operating system. "Mandiant Consulting was working closely with the victim organization and Juniper Networks on this investigation and providing Juniper Networks time to create mitigation tools and patches," Austin Larsen, principal threat analyst at Google Threat Intelligence Group, told The Register. The threat intel group won't disclose the victim's sector or region, but noted that typically UNC3886 targets defense, technology, and telecommunication organizations located in the US and Asia. When asked how many routers were compromised in the victim's environment, Larsen said it was a "significant number of devices." Aside from maintaining a presence on the devices, Mandiant did not say what the snoops were hunting for in ...

Read full article

Affected Software

4 affected components
Juniper Networks MX routers
Juniper Networks Junos OS
Juniper Networks MX routers
Juniper Networks Junos OS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of outdated Juniper Networks routers by Chinese spies who have installed backdoors to gain root access.

2

What security implications are discussed?

The article highlights the risks associated with using end-of-life network equipment that can be easily compromised, leading to unauthorized access and potential data breaches.

3

What products or software are affected?

The affected products include Juniper Networks MX routers and the Junos OS software.

4

How long have the Chinese spies been exploiting these devices?

Chinese spies have reportedly exploited these outdated Juniper routers for several months.

5

What recommendations are given to mitigate this security issue?

The article suggests that organizations should avoid using end-of-life hardware and ensure their network equipment is regularly updated and patched.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203