C0056: RedPenguin
The RedPenguin project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. RedPenguin activity was separately attributed to UNC3886 and included the deployment of multiple custom versions of the publicly-available TINYSHELL backdoor on Juniper routers.[1][2]
Security context for executives and security teams
C0056: RedPenguin describes The [RedPenguin](https://attack.mitre.org/campaigns/C0056) project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. [RedPenguin](https://attack.mitre.org/campaigns/C0056) activity was separately attributed to [UNC3886](https://attack.mitre.org/groups/G1048) and included the deployment of multiple custom versions of the publicly-available TINYSHELL backdoor on Juniper routers.(Citation: Juniper RedPenguin MAR 2025)(Citation: Mandiant UNC3886 Juniper Router...
Executive priority
C0056: RedPenguin is an official MITRE ATT&CK campaign. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate C0056: RedPenguin by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether C0056: RedPenguin appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
RedPenguin
The RedPenguin project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. RedPenguin activity was separately attributed to UNC3886 and included the deployment of multiple custom versions of the publicly-available TINYSHELL backdoor on Juniper routers.[1][2]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1057 | Process Discovery | During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon.[1] |
| Enterprise | T1040 | Network Sniffing | During RedPenguin, UNC3886 used a passive backdoor to act as a libpcap-based packet sniffer.[2] |
| Enterprise | T1587.001 | MalwareSub-technique | During RedPenguin, UNC3886 deployed custom malware based on the publicly-available TINYSHELL backdoor.[2]CitationCensys RedPenguin MAR 2025 |
| Enterprise | T1104 | Multi-Stage Channels | During RedPenguin, UNC3886 used malware with separate channels to request and carry out tasks from C2.[2] |
| Enterprise | T1059.008 | Network Device CLISub-technique | During RedPenguin, UNC3886 accessed the Junos OS CLI on targeted devices.[2][1] |
| Enterprise | T1571 | Non-Standard Port | During RedPenguin, UNC3886 used a backdoor that binds to port 45678 by default.[2] |
| Enterprise | T1070.007 | Clear Network Connection History and ConfigurationsSub-technique | During RedPenguin, UNC3886 used an implant to delete logs associated with unauthorized access to targeted Junos OS devices.[1] |
| Enterprise | T1078 | Valid Accounts | During RedPenguin, UNC3886 used legitimate credentials to gain priviliged access to Juniper routers.[2]CitationCensys RedPenguin MAR 2025 |
| Enterprise | T1059.004 | Unix ShellSub-technique | During RedPenguin, UNC3886 used malware capable of launching an interactive shell.[2][1] |
| Enterprise | T1203 | Exploitation for Client Execution | During RedPenguin, UNC3886 exploited CVE-2025-21590 to bypass Veriexec protections in Junos OS designed to prevent unauthorized binary execution.[2][1] |
| Enterprise | T1573.001 | Symmetric CryptographySub-technique | During RedPenguin, UNC3886 malware used the RC4 cipher to encrypt outgoing C2 messages.[1] |
| Enterprise | T1016 | System Network Configuration Discovery | During RedPenguin, UNC3886 leveraged JunoOS CLI queries to obtain the interface index which contains system and network details.[2][1] |
| Enterprise | T1090 | Proxy | During RedPenguin, UNC3886 used malware capable of establishing a SOCKS proxy connection to a specified IP and port.[2][1] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | During RedPenguin, UNC3886 created multiple strains of malware using names to mimic legitimate binaries such as appid, to, irad, lmpad, jdosd, and oemd.[2] |
| Enterprise | T1055 | Process Injection | During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.[2][1] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | During RedPenguin, UNC3886 used malware implants to deobfuscate incoming C2 messages and encoded archives.[2][1] |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | During RedPenguin, UNC3886 generated Base64-encoded files in the FreeBSD shell environment of targeted Juniper devices.[2][1] |
| Enterprise | T1205 | Traffic Signaling | During RedPenguin, UNC3886 leveraged malware capable of inpecting packets for a magic-string to activate backdoor functionalities.[2] |
| Enterprise | T1690 | Prevent Command History Logging | During RedPenguin, UNC3886 used malware to clear the `HISTFILE` environmental variable and to inject into Junos OS processes to inhibit logging.[2][1] |
| Enterprise | T1105 | Ingress Tool Transfer | During RedPenguin, UNC3886 used backdoor malware capable of downloading files to compromised infrastructure.[2] |
| Enterprise | T1090.003 | Multi-hop ProxySub-technique | During RedPenguin, UNC3886 used infrastructure associated with operational relay box (ORB) networks.[2] |
| Enterprise | T1095 | Non-Application Layer Protocol | During RedPenguin, UNC3886 leveraged malware that used UDP and TCP sockets for C2.[2]CitationCensys RedPenguin MAR 2025[1] |
| Enterprise | T1554 | Compromise Host Software Binary | During RedPenguin, UNC3886 peformed a local memory patching attack to modify the snmpd and mgd Junos OS daemons.[1] |
| Enterprise | T1070.004 | File DeletionSub-technique | During RedPenguin, UNC3886 used malware capaple of removing scripts after execution.[2] |
| Enterprise | T1014 | Rootkit | During RedPenguin, UNC3886 used rootkits such as REPTILE and MEDUSA.[2] |
| Enterprise | T1041 | Exfiltration Over C2 Channel | During RedPenguin, UNC3886 uploaded specified files from compromised devices to a remote server. [2] |
Groups, software, and campaigns
G1048: UNC3886
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.[1][2]
S1219: REPTILE
S1220: MEDUSA
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | e13e61e03e50… | ||
| 19.1 | 1.0 | Older bundle | 271f2538f23c… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Juniper RedPenguin MAR 2025
Juniper Networks, Cybersecurity R&D. (2025, March 11). The RedPenguin Malware Incident. Retrieved June 24, 2025.
Open source URL - [2]Mandiant UNC3886 Juniper Routers MAR 2025
Lamparski, L. et al. (2025, March 11). Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers. Retrieved June 24, 2025.
Open source URL - [3]mitre-attackC0056Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
