J-magic is a stealthy passive backdoor associated with compromises of enterprise-grade Juniper edge devices, including systems functioning as VPN gateways. Active from at least mid-2023 into mid-2024, it is notable for using Extended Berkeley Packet Filter functionality to inspect network traffic on selected interfaces and ports while remaining dormant until it detects a specially crafted magic packet. Upon activation, it can initiate a reverse shell, enabling covert operator access without exposing a conventional listening service under normal conditions.
The malware includes packet-capture and filtering logic that monitors inbound TCP traffic and can communicate with command-and-control infrastructure over SSL. Its design emphasizes low observability on network appliances and edge infrastructure, where endpoint security coverage is often limited. J-magic also employs defense-evasion measures such as masquerading as a legitimate kernel-thread-like process name to blend into Linux process listings.
Observed targeting has centered on Juniper edge devices in enterprise environments, with a significant share of affected systems appearing to serve as VPN gateways. J-magic is part of a broader class of Linux and network-device implants, alongside families such as BPFDoor and Symbiote, that use packet-filtering mechanisms and magic-packet activation to create covert access channels on infrastructure systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
The "magic packet" concept (TCP SYN with a window of 54321) is a form of traffic signaling to activate the passive C2.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign/tool observed targeting infrastructure outside normal endpoint visibility, with many targeted devices appearing to be VPN gateways.
A backdoor loaded into enterprise-grade Juniper routers and described alongside other magic-packet malware.
Custom backdoor for Juniper routers that monitors for a 'magic packet' in TCP traffic to trigger attacker control/persistence.
Referenced as an example of eBPF-abusing passive backdoor that monitors traffic and activates on a ‘magic packet’.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.