ATT&CKCampaignsJ-magic Campaign

J-magic Campaign

C0050

Campaign, Jun 2023 to Jun 2024.View on attack.mitre.org

About this campaign

The J-magic Campaign was active from mid-2023 to at least mid-2024 and featured the use of the J-magic backdoor, a custom cd00r variant tailored for use against Juniper routers. The J-magic Campaign targeted Junos OS routers serving as VPN gateways primarily in the semiconductor, energy, manufacturing, and IT sectors.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

During the J-magic Campaign, threat actors used the name “JunoscriptService” to masquerade malware as the Junos automation scripting service.

T1583.003
Virtual Private Server

During the J-magic Campaign, threat actors acquired VPS for use in C2.

T1587.003
Digital Certificates

During the J-magic Campaign, threat actors used self-signed certificates on VPS C2 infrastructure.

T1588.001
Malware

During the J-magic Campaign campaign, threat actors used open-source malware post-compromise including a custom variant of the cd00r backdoor.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software1

References1

  1. Lumen J-Magic JAN 2025 Open source
    Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.