Skip to content

Malware

J-Magic

According to Lumen, J-Magic is a variant of cd00r and passively scans for five different predefined parameters before activating.

J-Magic is a Linux malware family.

Background

According to Lumen, J-Magic is a cd00r variant that stays passive, watching for five specific predefined parameters before it activates. When one of these parameters, or "magic packets," arrives, the implant replies with a secondary challenge. After that challenge is satisfied, J-Magic opens a reverse shell on the local file system, giving the operators the ability to control the device, exfiltrate data, or install additional malware.


Source: Malpedia (Fraunhofer FKIE).