Product Affected

This bulletin pertains to all versions of Junos OS.
None

Problem

Summary


In July 2024, the Juniper Cybersecurity R&D team received a report from the field regarding a potential malware infection of a set of MX Series routers. The team launched a project – codenamed RedPenguin – with the following goals:

  1. confirm that the routers were impacted by malicious software implants;
  2. understand the malware designs and implementations;
  3. assess how the malware was able to run on Junos OS routers, which are protected with the veriexec runtime integrity subsystem;
  4. formulate recommendations to minimize the malware risk.

 

Customers are advised to review the attached PDF document to familiarize themselves with the details of this issue.

Solution

To assist customers and others to identify the implants, hashes for each of the malware binaries are available in the Malware Analysis section of the attached document. Additionally, Junos OS includes the Juniper Malware Removal Tool (JMRT), which can be used on the router host to scan for the malwares. See Juniper Malware Removal Tool

Workaround

Please refer to JSA93446 [juniper.net]

Modification History

2025-03-12: Initial Publication

2025-03-12/2: Fixed the link to the Juniper Malware Removal Tool web page

 

Related Information