Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareJ-magic | J-magic can compare the host and remote IPs to check if a received packet is from the infected machine. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareJ-magic | J-magic can rename itself as “[nfsiod 0]” to masquerade as the local Network File System (NFS) asynchronous I/O server. |
| T1040 Network Sniffing |
MalwareJ-magic | J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports. |
| T1059.004 Unix Shell |
MalwareJ-magic | The J-magic agent is executed through a command line argument which specifies an interface and listening port. |
| T1070.003 Clear Command History |
MalwareJ-magic | J-magic can overwrite previously executed command line arguments. |
| T1095 Non-Application Layer Protocol |
MalwareJ-magic | J-magic can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1095 Non-Application Layer Protocol |
Malwarecd00r | cd00r can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1205 Traffic Signaling |
MalwareJ-magic | J-magic can monitor TCP traffic for packets containing one of five different predefined parameters and will spawn a reverse shell if one of the parameters and the proper response string to a subsequent challenge is received. |
| T1205.001 Port Knocking |
Malwarecd00r | cd00r can monitor for a single TCP-SYN packet to be sent in series to a configurable set of ports (200, 80, 22, 53 and 3 in the original code) before opening a port for communication. |
| T1573.002 Asymmetric Cryptography |
MalwareJ-magic | J-magic can communicate back to send a challenge to C2 infrastructure over SSL. |
| T1583.003 Virtual Private Server |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors acquired VPS for use in C2. |
| T1587.003 Digital Certificates |
CampaignJ-magic Campaign | During the J-magic Campaign, threat actors used self-signed certificates on VPS C2 infrastructure. |
| T1588.001 Malware |
CampaignJ-magic Campaign | During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.