ATT&CKReferencesLumen J-Magic JAN 2025

Lumen J-Magic JAN 2025

Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns1

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareJ-magic

J-magic can compare the host and remote IPs to check if a received packet is from the infected machine.

T1036.005
Match Legitimate Resource Name or Location
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service.

T1036.005
Match Legitimate Resource Name or Location
MalwareJ-magic

J-magic can rename itself as “[nfsiod 0]” to masquerade as the local Network File System (NFS) asynchronous I/O server.

T1040
Network Sniffing
MalwareJ-magic

J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports.

T1059.004
Unix Shell
MalwareJ-magic

The J-magic agent is executed through a command line argument which specifies an interface and listening port.

T1070.003
Clear Command History
MalwareJ-magic

J-magic can overwrite previously executed command line arguments.

T1095
Non-Application Layer Protocol
MalwareJ-magic

J-magic can monitor incoming C2 communications sent over TCP to the compromised host.

T1095
Non-Application Layer Protocol
Malwarecd00r

cd00r can monitor incoming C2 communications sent over TCP to the compromised host.

T1205
Traffic Signaling
MalwareJ-magic

J-magic can monitor TCP traffic for packets containing one of five different predefined parameters and will spawn a reverse shell if one of the parameters and the proper response string to a subsequent challenge is received.

T1205.001
Port Knocking
Malwarecd00r

cd00r can monitor for a single TCP-SYN packet to be sent in series to a configurable set of ports (200, 80, 22, 53 and 3 in the original code) before opening a port for communication.

T1573.002
Asymmetric Cryptography
MalwareJ-magic

J-magic can communicate back to send a challenge to C2 infrastructure over SSL.

T1583.003
Virtual Private Server
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors acquired VPS for use in C2.

T1587.003
Digital Certificates
CampaignJ-magic Campaign

During the J-magic Campaign, threat actors used self-signed certificates on VPS C2 infrastructure.

T1588.001
Malware
CampaignJ-magic Campaign

During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.