Juniper Networks, Cybersecurity R&D. (2025, March 11). The RedPenguin Malware Incident. Retrieved June 24, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details. |
| T1027.013 Encrypted/Encoded File |
CampaignRedPenguin | During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices. |
| T1055 Process Injection |
CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes. |
| T1057 Process Discovery |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon. |
| T1059.004 Unix Shell |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of launching an interactive shell. |
| T1059.008 Network Device CLI |
CampaignRedPenguin | During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices. |
| T1070.007 Clear Network Connection History and Configurations |
CampaignRedPenguin | During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices. |
| T1090 Proxy |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port. |
| T1095 Non-Application Layer Protocol |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives. |
| T1203 Exploitation for Client Execution |
CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution. |
| T1554 Compromise Host Software Binary |
CampaignRedPenguin | During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons. |
| T1573.001 Symmetric Cryptography |
CampaignRedPenguin | During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages. |
| T1690 Prevent Command History Logging |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.