ATT&CKReferencesJuniper RedPenguin MAR 2025

Juniper RedPenguin MAR 2025

Juniper Networks, Cybersecurity R&D. (2025, March 11). The RedPenguin Malware Incident. Retrieved June 24, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details.

T1027.013
Encrypted/Encoded File
CampaignRedPenguin

During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices.

T1055
Process Injection
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.

T1057
Process Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon.

T1059.004
Unix Shell
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of launching an interactive shell.

T1059.008
Network Device CLI
CampaignRedPenguin

During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices.

T1070.007
Clear Network Connection History and Configurations
CampaignRedPenguin

During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices.

T1090
Proxy
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.

T1095
Non-Application Layer Protocol
CampaignRedPenguin

During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2.

T1140
Deobfuscate/Decode Files or Information
CampaignRedPenguin

During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives.

T1203
Exploitation for Client Execution
CampaignRedPenguin

During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution.

T1554
Compromise Host Software Binary
CampaignRedPenguin

During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons.

T1573.001
Symmetric Cryptography
CampaignRedPenguin

During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages.

T1690
Prevent Command History Logging
CampaignRedPenguin

During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.