ATT&CKReferencesMandiant UNC3886 Juniper Routers MAR 2025

Mandiant UNC3886 Juniper Routers MAR 2025

Lamparski, L. et al. (2025, March 11). Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers. Retrieved June 24, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples22

TechniqueUsed byProcedure example
T1014
Rootkit
CampaignRedPenguin

During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA.

T1016
System Network Configuration Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details.

T1027.013
Encrypted/Encoded File
CampaignRedPenguin

During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices.

T1036.005
Match Legitimate Resource Name or Location
CampaignRedPenguin

During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd.

T1040
Network Sniffing
CampaignRedPenguin

During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer.

T1041
Exfiltration Over C2 Channel
CampaignRedPenguin

During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server.

T1055
Process Injection
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.

T1059.004
Unix Shell
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of launching an interactive shell.

T1059.008
Network Device CLI
CampaignRedPenguin

During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices.

T1070.004
File Deletion
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capaple of removing scripts after execution.

T1078
Valid Accounts
CampaignRedPenguin

During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers.

T1090
Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.

T1090.003
Multi-hop Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks.

T1095
Non-Application Layer Protocol
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2.

T1104
Multi-Stage Channels
CampaignRedPenguin

During RedPenguin, UNC3886 used malware with separate channels to request and carry out tasks from C2.

T1105
Ingress Tool Transfer
CampaignRedPenguin

During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure.

T1140
Deobfuscate/Decode Files or Information
CampaignRedPenguin

During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives.

T1203
Exploitation for Client Execution
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution.

T1205
Traffic Signaling
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware capable of inpecting packets for a magic-string to activate backdoor functionalities.

T1571
Non-Standard Port
CampaignRedPenguin

During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default.

T1587.001
Malware
CampaignRedPenguin

During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor.

T1690
Prevent Command History Logging
CampaignRedPenguin

During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.