China-linked APT UNC3886 deploys custom backdoors on Juniper Networks Junos OS MX routers.
Mandiant researchers discover TINYSHELL-based backdoors on Juniper MX routers targeting defense, technology, and telecommunications sectors in the US and Asia.
UNC3886 demonstrates in-depth knowledge of system internals and uses compromised credentials to access Junos OS CLI from terminal servers.
Mandiant provides Indicators of Compromise (IoCs) and Yara rules to detect the backdoors.