ATT&CKCampaignsRedPenguin

RedPenguin

C0056

Campaign, Jul 2024 to Mar 2025.View on attack.mitre.org

About this campaign

The RedPenguin project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. RedPenguin activity was separately attributed to UNC3886 and included the deployment of multiple custom versions of the publicly-available TINYSHELL backdoor on Juniper routers.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1014
Rootkit

During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA.

T1016
System Network Configuration Discovery

During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details.

T1027.013
Encrypted/Encoded File

During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices.

T1036.005
Match Legitimate Resource Name or Location

During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd.

T1040
Network Sniffing

During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer.

T1041
Exfiltration Over C2 Channel

During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server.

T1055
Process Injection

During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.

T1057
Process Discovery

During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon.

T1059.004
Unix Shell

During RedPenguin, UNC3886 used malware capable of launching an interactive shell.

T1059.008
Network Device CLI

During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices.

T1070.004
File Deletion

During RedPenguin, UNC3886 used malware capaple of removing scripts after execution.

T1070.007
Clear Network Connection History and Configurations

During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices.

T1078
Valid Accounts

During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers.

T1090
Proxy

During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.

T1090.003
Multi-hop Proxy

During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks.

View all 26 procedure examples

Attributed groups1

Software2

References2

  1. Juniper RedPenguin MAR 2025 Open source
    Juniper Networks, Cybersecurity R&D. (2025, March 11). The RedPenguin Malware Incident. Retrieved June 24, 2025.
  2. Mandiant UNC3886 Juniper Routers MAR 2025 Open source
    Lamparski, L. et al. (2025, March 11). Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers. Retrieved June 24, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.