J-magic

S1203

Malware.View on attack.mitre.org

About this malware

J-magic is a custom variant of the cd00r backdoor tailored to target Juniper routers that was first observed during the J-magic Campaign in mid-2023. J-magic monitors TCP traffic for five predefined parameters or "magic packets" to be sent by the attackers before activating on compromised devices.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1016
System Network Configuration Discovery

J-magic can compare the host and remote IPs to check if a received packet is from the infected machine.

T1036.005
Match Legitimate Resource Name or Location

J-magic can rename itself as “[nfsiod 0]” to masquerade as the local Network File System (NFS) asynchronous I/O server.

T1040
Network Sniffing

J-magic has a pcap listener function that can create an Extended Berkley Packet Filter (eBPF) on designated interfaces and ports.

T1059.004
Unix Shell

The J-magic agent is executed through a command line argument which specifies an interface and listening port.

T1070.003
Clear Command History

J-magic can overwrite previously executed command line arguments.

T1095
Non-Application Layer Protocol

J-magic can monitor incoming C2 communications sent over TCP to the compromised host.

T1205
Traffic Signaling

J-magic can monitor TCP traffic for packets containing one of five different predefined parameters and will spawn a reverse shell if one of the parameters and the proper response string to a subsequent challenge is received.

T1573.002
Asymmetric Cryptography

J-magic can communicate back to send a challenge to C2 infrastructure over SSL.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Lumen J-Magic JAN 2025 Open source
    Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.