Lamparski, L. et al. (2025, March 11). Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers. Retrieved June 24, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
CampaignRedPenguin | During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA. |
| T1016 System Network Configuration Discovery |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details. |
| T1027.013 Encrypted/Encoded File |
CampaignRedPenguin | During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignRedPenguin | During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd. |
| T1040 Network Sniffing |
CampaignRedPenguin | During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer. |
| T1041 Exfiltration Over C2 Channel |
CampaignRedPenguin | During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server. |
| T1055 Process Injection |
CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes. |
| T1059.004 Unix Shell |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of launching an interactive shell. |
| T1059.008 Network Device CLI |
CampaignRedPenguin | During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices. |
| T1070.004 File Deletion |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capaple of removing scripts after execution. |
| T1078 Valid Accounts |
CampaignRedPenguin | During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers. |
| T1090 Proxy |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port. |
| T1090.003 Multi-hop Proxy |
CampaignRedPenguin | During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks. |
| T1095 Non-Application Layer Protocol |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2. |
| T1104 Multi-Stage Channels |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware with separate channels to request and carry out tasks from C2. |
| T1105 Ingress Tool Transfer |
CampaignRedPenguin | During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure. |
| T1140 Deobfuscate/Decode Files or Information |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives. |
| T1203 Exploitation for Client Execution |
CampaignRedPenguin | During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution. |
| T1205 Traffic Signaling |
CampaignRedPenguin | During RedPenguin, UNC3886 leveraged malware capable of inpecting packets for a magic-string to activate backdoor functionalities. |
| T1571 Non-Standard Port |
CampaignRedPenguin | During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default. |
| T1587.001 Malware |
CampaignRedPenguin | During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor. |
| T1690 Prevent Command History Logging |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.