{"id":1258,"date":"2026-06-10T17:11:44","date_gmt":"2026-06-10T17:11:44","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1258"},"modified":"2026-06-10T17:11:44","modified_gmt":"2026-06-10T17:11:44","slug":"china-linked-jdy-botnet-expands-to-1500-devices-for-cyber-reconnaissance","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1258","title":{"rendered":"China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgQC0_BYMuNpY7re4OHHsytEfC6fW3KsonxN6e2X0Dj03fJoMazI6EZnvPj_hOUZ99yJLq6RrH3ZSCsfDWOB6AgDJVk_1LY5TzgSpP7QFKcI_grjRI7Pm9QGputoI0LM4LH8ZCOAVb_PnzXAs_bMP6n_3u__fPEmxEKVUv5ZZjG5vOJT_fmhvAy551gjCmi\/s1700-e365\/bot.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have warned of a \u00abresurgence and expansion\u00bb of <b>JDY<\/b>, a covert network associated with China-nexus state-sponsored threat actors.<\/p>\n<p>\u00abThe JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale,\u00bb Lumen&#8217;s Black Lotus Labs <a href=\"https:\/\/www.lumen.com\/blog\/en-us\/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation\">said<\/a> in a report shared with The Hacker News.<\/p>\n<p>JDY was first flagged as a cluster within another botnet codenamed KV-botnet in mid-December 2023. Primarily used for broader scanning against internet targets, the stealthy network comprising compromised SOHO routers, firewalls, and IoT devices has been put to use by Chinese hacking groups like Volt Typhoon.<\/p>\n<p>Following KV-botnet&#8217;s takedown by the U.S. government in early 2024, the botnet operators began making behavioral changes to the network, with the second KV cluster largely going offline. It&#8217;s suspected that the botnet is offered by the operators to various hacking outfits, while carrying out reconnaissance and targeting on their own.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The latest findings from Black Lotus Labs show that the malware has expanded in scope to infect a broader range of devices and act as a conduit to feed \u00abstructured reconnaissance data\u00bb into a larger scanning ecosystem for follow-on target identification and exploitation.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Specifically, the JDY cluster is being used to conduct targeted scanning and service fingerprinting with an aim to flag vulnerable infrastructure following public disclosures. This points to an industrialized reconnaissance effort, the results of which are leveraged by Chinese nation-state groups.<\/p>\n<p>This has been complemented by a growth in the botnet&#8217;s size, which has surged from 650 bots at the start of January 2024 to more than 1,500 compromised devices. Most of the hacked nodes are located in the U.S. and Brazil, followed by Europe and Asia.<\/p>\n<p>Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.<\/p>\n<p>\u00abThe botnet&#8217;s large number of U.S.-based SOHO\/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists,\u00bb Black Lotus Labs said.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQL6fTNPWNduBq1hES8YHazXhjhWjbeGQTQi_X0TFvBXGFXPqLFIc9uAcYAy_QQQY-oe-9qW_EfPp3xu0TF6i7vX7BwbNoNmf8kVRQhuEq_nLwBaMwP91-OOb19mFrZErw3Fofba3KsTXme4AeoSK7e8g1a4l-NwPXiLGI4sfzK4R3FVEUxEL70MLe7i80\/s1700-e365\/botnet.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQL6fTNPWNduBq1hES8YHazXhjhWjbeGQTQi_X0TFvBXGFXPqLFIc9uAcYAy_QQQY-oe-9qW_EfPp3xu0TF6i7vX7BwbNoNmf8kVRQhuEq_nLwBaMwP91-OOb19mFrZErw3Fofba3KsTXme4AeoSK7e8g1a4l-NwPXiLGI4sfzK4R3FVEUxEL70MLe7i80\/s1700-e365\/botnet.jpg\" alt=\"\" border=\"0\" data-original-height=\"387\" data-original-width=\"900\"\/><\/a><\/div>\n<p>\u00abBy distributing their scanning and reconnaissance activity across a wide range of IP addresses, the operators make it less likely that any single IP will be labeled as a scanner and blocked. Additionally, using compromised SOHO and IoT devices helps this activity blend in with legitimate user traffic.\u00bb<\/p>\n<p>The architecture that powers the botnet is best described as layered: the operators use Tor nodes to manage infected infrastructure, including both the command-and-control (C2) and payload servers. The C2 servers direct the bots to perform targeted reconnaissance and system profiling, as opposed to indiscriminate scanning. Results of the scans are sent to central servers for ongoing intelligence gathering in an effort to further Chinese threat actors&#8217; objectives.<\/p>\n<p>Attack chains weaponize newly disclosed vulnerabilities in edge devices (e.g., CVE-2026-35616) to deliver a shell script dropper that checks if the malware is already active, and if not, proceeds to download the primary payload based on the detected processor architecture (e.g., mips, mips64, mipsel, or mipsel64). Once the malware is launched, it&#8217;s deleted from disk.<\/p>\n<p>The malware that facilitates scanning and target reconnaissance is designed to fingerprint the host, receive scanning tasks from a central C2 server, carry out high-volume TCP, SSL, UDP, and ICMP-assisted probing, capture responses (TLS certificates, metadata, etc.), and report the results back to the dispatch server. The goal is to conduct infrastructure reconnaissance rather than exploitation.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A noteworthy functionality of the malware is its ability to adapt its scanning methodology based on its privileges on the local system. If it can open a raw socket, an indication of root privileges, it initiates high-speed <a href=\"https:\/\/nmap.org\/book\/synscan.html\">SYN scanning<\/a> using custom-crafted TCP packets. If raw sockets are unavailable or if the task is a web scan, the scanning engine resorts to using standard TCP and TLS connections or employs protocols like UDP and ICMP.<\/p>\n<p>This activity most likely informs asset discovery, vulnerability-targeting pipelines, and downstream exploitation or attack-orchestration systems, the cybersecurity company said.<\/p>\n<p>\u00abJDY demonstrates how IoT\/SOHO botnets and covert networks of compromised devices are being used for rapid vulnerability exploitation,\u00bb the company said. \u00abJDY&#8217;s growth and continued operation illustrate how modern reconnaissance networks persist despite takedowns and adapt as a durable capability within a broader adversary ecosystem.\u00bb<\/p>\n<p>\u00abJDY&#8217;s evolution from a supporting component of the KV-botnet to an independent, high-performance reconnaissance capability demonstrates that disruption of individual nodes or clusters does not eliminate the underlying capability. The capability persists, adapts, and continues to provide adversaries with timely targeting data, often within hours of vulnerability disclosure.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have warned of a \u00abresurgence and expansion\u00bb of JDY, a covert network associated with China-nexus state-sponsored threat actors. \u00abThe JDY botnet comprises over 1,500 SOHO [small office and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1259,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[192,479,233,175,206,1996,1997],"class_list":["post-1258","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-botnet","tag-chinalinked","tag-cyber","tag-devices","tag-expands","tag-jdy","tag-reconnaissance"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1258"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1258\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1259"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}