Mandiant and Juniper disclosed that the China-linked espionage group UNC3886 compromised end-of-life Juniper MX routers running Junos OS and deployed six TINYSHELL backdoor variants to maintain long-term access. Investigators said the campaign began by mid-2024 and marked an evolution in the actor’s tradecraft, shifting from prior targeting of virtualization and edge technologies to internal networking infrastructure. The malware set included active and passive backdoor variants, and the attackers used an embedded script to disable logging and reduce the chance of detection.
Juniper released updates for a medium-severity Junos OS kernel vulnerability affecting Junos OS products except Junos Evolved, saying exploitation requires a local attacker with high privileges to inject code into a device. Mandiant also described a novel process-injection technique used to bypass built-in protections and said it found no overlap with the broader Volt Typhoon or Salt Typhoon campaigns. Organizations were urged to upgrade to current Juniper images and run the Juniper Malware Removal Tool Quick Scan and Integrity Check on exposed devices.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Juniper later released software updates to address the underlying medium-severity Junos OS kernel vulnerability tied to the backdoor campaign. The company said the issue affects all Junos OS products except Junos Evolved and requires a local high-privilege attacker to inject code into a device.
Alongside the disclosure, Juniper published a related security advisory and recommended that customers upgrade affected devices to the latest Juniper images. Guidance also included using the Juniper Malware Removal Tool Quick Scan and Integrity Check.
On publication of Mandiant's report, the companies disclosed the months-long investigation into UNC3886's compromise of Juniper routers and attributed the activity to the China-nexus espionage actor. Mandiant said it found no overlap with Volt Typhoon or Salt Typhoon and characterized the operation as an evolution of UNC3886 tradecraft.
During the campaign, UNC3886 installed a custom malware ecosystem on compromised Junos OS devices, including six distinct TINYSHELL backdoor variants. Mandiant also identified a novel process-injection technique and scripts designed to disable logging and preserve stealthy persistence.
Mandiant said its investigation traced a China-linked UNC3886 campaign back to mid-2024, when the actor targeted end-of-life Juniper MX routers. The activity marked a shift toward compromising internal networking infrastructure for espionage purposes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
sdxcentral.com
Open sourcesupportportal.juniper.net
Open sourceaustinlarsen.me
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.