s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.j_magic

📛 Threat Title

Malware family: J-Magic

Category: J-Magic First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.j_magic`. Printable name: J-Magic.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    J-magic is a custom variant of the cd00r backdoor tailored to target Juniper routers that was first observed during the J-magic Campaign in mid-2023. J-magic monitors TCP traffic for five predefined parameters or " magic packets" to be sent by the attackers before activating on compromised devices.

  • web:cyberpress.org

    Incorporating an encrypted RSA-based challenge-response mechanism to prevent unauthorized access. While there are similarities to the "SeaSpy" malware family , such as overlapping function names and a shared use of cd00r, J-Magic's unique certificate-based challenge-response suggests advancements in operational security.

  • web:cyberscoop.com

    The malware scans for five different predefined parameters before activating. If any of these parameters or " magic packets" are received, the malware sends a confirmation request. Once confirmed, J-Magic establishes a reverse shell on the local file system, allowing operators to control the device, steal data, or deploy further malware .

  • web:itinnovationstation.com

    Conclusion The J-Magic malware campaign is a highly sophisticated and stealthy attack that specifically targets Juniper routers, employing magic packet activation to evade detection. Given its ability to provide long-term, covert access to critical infrastructure, this malware poses a significant risk to organizations relying on Juniper hardware.

  • web:itsecuritynewsbox.com

    The J-magic campaign is notable for targeting JunoOS, a FreeBSD-based operating system that threat actors rarely target in malware attacks. Lumen's telemetry shows that roughly 50% of the targeted enterprise devices are configured as a virtual private network (VPN) gateway.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Lumen, J-Magic is a variant of cd00r and passively scans for five different predefined parameters before activating. If any of these parameters or " magic packets" are received, the agent sends back a secondary challenge. Once that challenge is complete, J-magic establishes a reverse shell on the local file system, allowing the operators to control the device, steal data, or ...

  • web:thehackernews.com

    Rare malware targets Juniper routers in the J-magic campaign, exploiting JunoOS and impacting industries like IT, energy, and manufacturing.

  • web:undercodenews.com

    The Rise of Stealthy Malware J-Magic's use of an in-memory-only approach and its reliance on passive monitoring for " magic packets" demonstrate a significant leap in malware sophistication. By avoiding persistent storage and only activating upon specific triggers, the malware effectively evades traditional detection mechanisms.

  • web:www.bleepingcomputer.com

    A malicious campaign has been specifically targeting Juniper edge devices, many acting as VPN gateways, with malware dubbed J-magic that starts a reverse shell only if it detects a " magic packet ...

  • web:www.lumen.com

    Black Lotus Labs uncovered the threat of magic packet malware in the J-magic campaign targeting Juniper routers. Read ther analysis.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.