Campaign, Jun 2023 to Jun 2024.View on attack.mitre.org
The J-magic Campaign was active from mid-2023 to at least mid-2024 and featured the use of the J-magic backdoor, a custom cd00r variant tailored for use against Juniper routers. The J-magic Campaign targeted Junos OS routers serving as VPN gateways primarily in the semiconductor, energy, manufacturing, and IT sectors.
| Technique | Procedure example |
|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service. |
| T1583.003 Virtual Private Server |
During the J-magic Campaign, threat actors acquired VPS for use in C2. |
| T1587.003 Digital Certificates |
During the J-magic Campaign, threat actors used self-signed certificates on VPS C2 infrastructure. |
| T1588.001 Malware |
During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.