J-magic

MITRE ATT&CK: S1203 View on attack.mitre.org

Aliases: J-magic

First seen
2023-06-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 14:26:14

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

J-magic is a custom variant of the cd00r backdoor tailored to target Juniper routers that was first observed during the J-magic Campaign in mid-2023. J-magic monitors TCP traffic for five predefined parameters or "magic packets" to be sent by the attackers before activating on compromised devices.

Detection coverage

  • 59 Sigma rules

Malware & tools used

  • Match Legitimate Resource Name or Location (attack-pattern)
  • Clear Command History (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Traffic Signaling (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Unix Shell (attack-pattern)

Used by threat actors

  • J-magic Campaign (campaign)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.J Magic (report)
  • blog.lumen.com — The J Magic Show Magic Packets And Where To Find Them (report)
  • MITRE ATT&CK — S1203 (report)

External references