Mandiant and Juniper disclosed that the China-linked espionage group UNC3886 compromised Juniper MX routers running end-of-life Junos OS and deployed multiple TinyShell-based backdoors designed for stealth and persistence. Investigators said the actor used legitimate stolen credentials to access a terminal server, dropped into the underlying FreeBSD shell, staged Base64-encoded compressed payloads, and injected malicious code into the memory of a legitimate process to evade Junos OS veriexec protections. The campaign also used an embedded script to disable logging, and researchers recovered as many as six backdoor variants with different command-and-control methods.
Juniper tied the technique to CVE-2025-21590, an actively exploited flaw that lets a local authenticated attacker with shell access bypass veriexec, execute malicious code, and fully compromise affected devices. The company issued fixes across multiple Junos OS release trains and urged customers to upgrade to supported images, run the Juniper Malware Removal Tool quick and integrity scans, and review logs and indicators of compromise. Mandiant said it found no technical overlap between this activity and publicly reported Volt Typhoon or Salt Typhoon operations.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Juniper released security updates for Junos OS to address CVE-2025-21590, a vulnerability that lets a local authenticated attacker with shell access bypass Veriexec and execute malicious code. The flaw was described as actively exploited, and Juniper recommended immediate patching and use of the Juniper Malware Removal Tool scans.
Juniper published bulletin JSA93446 covering CVE-2025-21590, the Veriexec bypass tied to the reported router compromises. The bulletin is referenced by Mandiant as the tracking and remediation notice for the issue.
In mid-2024, Mandiant reported that China-nexus espionage group UNC3886 deployed multiple TINYSHELL-based backdoors on Juniper Networks Junos OS routers and used a script to disable logging for stealth and persistence. The intrusions involved stolen legitimate credentials, access to the FreeBSD shell, and payload execution from router memory.
On its March 12, 2025 publication, Mandiant disclosed details of the Juniper router espionage campaign and attributed it to UNC3886. The report also said Mandiant had not identified technical overlaps with publicly reported Volt Typhoon or Salt Typhoon activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
supportportal.juniper.net
Open sourcecsirt.sk
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.