J-magic is a custom backdoor targeting enterprise-grade Juniper edge devices, including routers, with many observed targets appearing to function as VPN gateways. Black Lotus Labs reported that the malware starts a reverse shell only after detecting a specially crafted "magic packet" in network traffic, making it a passive backdoor designed for stealth. The malware can monitor incoming C2 communications sent over TCP to the compromised host, includes a pcap listener that can create an Extended Berkeley Packet Filter (eBPF) on designated interfaces and ports, and can communicate back by sending a challenge to command-and-control infrastructure over SSL. It can rename itself as "[nfsiod 0]" to masquerade as the local NFS asynchronous I/O server. Reporting places J-magic activity beginning in mid-2023 and continuing into at least mid-2024; telemetry from March through September 2024 identified 36 unique IP addresses matching its signature conditions, representing less than 0.01% of analyzed NetFlow, and about 50% of targeted devices appeared to be VPN gateways. The malware has been cited alongside BPFDoor, Symbiote, and SEASPY as demonstrating the use of eBPF or similar packet-filtering techniques for passive, stealthy backdoors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
Cyclops Blink can rename its running process to [kworker:0/1] to masquerade as a Linux kernel thread.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign/tool observed targeting infrastructure outside normal endpoint visibility, with many targeted devices appearing to be VPN gateways.
A backdoor loaded into enterprise-grade Juniper routers and described alongside other magic-packet malware.
Custom backdoor for Juniper routers that monitors for a 'magic packet' in TCP traffic to trigger attacker control/persistence.
Referenced as an example of eBPF-abusing passive backdoor that monitors traffic and activates on a ‘magic packet’.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.