Summary
In July 2024, the Juniper Cybersecurity R&D team received a report from the field regarding a potential malware infection of a set of MX Series routers. The team launched a project – codenamed RedPenguin – with the following goals:
Customers are advised to review the attached PDF document to familiarize themselves with the details of this issue.
To assist customers and others to identify the implants, hashes for each of the malware binaries are available in the Malware Analysis section of the attached document. Additionally, Junos OS includes the Juniper Malware Removal Tool (JMRT), which can be used on the router host to scan for the malwares. See Juniper Malware Removal Tool
Please refer to JSA93446 [juniper.net]
2025-03-12: Initial Publication
2025-03-12/2: Fixed the link to the Juniper Malware Removal Tool web page