J-magic
MITRE ATT&CK: S1203 View on attack.mitre.org
Aliases: J-magic
- First seen
- 2023-06-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- network-devices
- Profile updated
- 2026-07-07 14:26:14
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
J-magic is a custom variant of the cd00r backdoor tailored to target Juniper routers that was first observed during the J-magic Campaign in mid-2023. J-magic monitors TCP traffic for five predefined parameters or "magic packets" to be sent by the attackers before activating on compromised devices.
Detection coverage
- 59 Sigma rules
Malware & tools used
- Match Legitimate Resource Name or Location (attack-pattern)
- Clear Command History (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Traffic Signaling (attack-pattern)
- Network Sniffing (attack-pattern)
- Unix Shell (attack-pattern)
Used by threat actors
- J-magic Campaign (campaign)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.J Magic (report)
- blog.lumen.com — The J Magic Show Magic Packets And Where To Find Them (report)
- MITRE ATT&CK — S1203 (report)