BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Linked JDY Botnet Expands, Infects 1,500 Devices

Chinese state-linked JDY botnet grows, scans for vulnerabilities to exploit.

  • The JDY botnet, used by Chinese state-sponsored hacking groups like Volt Typhoon, has rapidly expanded to over 1,500 compromised SOHO routers and IoT devices.
  • Its operators have diversified their targets to include devices from Ubiquiti, Hikvision, Linksys, and others, primarily located in the U.S. and Brazil.
  • The network functions as a centralized, high-performance scanner for targeted reconnaissance, feeding data into a larger ecosystem for exploitation shortly after vulnerabilities are disclosed.

Cybersecurity researchers at Lumen’s Black Lotus Labs have documented a resurgence and expansion of the JDY botnet, a covert network linked to China-nexus state-sponsored actors. The findings, detailed in a report shared with The Hacker News, show its growth from 650 bots in January 2024 to more than 1,500 compromised devices today. This industrialized reconnaissance effort enables Chinese nation-state groups to rapidly identify vulnerable infrastructure following public disclosures.
Initially flagged within the KV-botnet cluster in late 2023, JDY evolved into an independent capability after the U.S. government’s takedown of KV-botnet in early 2024. Consequently, the botnet now serves as a conduit for feeding structured reconnaissance data into a larger scanning ecosystem. The malware’s architecture uses Tor nodes to manage command-and-control servers, which direct bots to perform targeted system profiling and scanning.
Moreover, the malware’s scanning methodology adapts based on its local privileges, using high-speed SYN scanning when root access is available. This activity informs downstream exploitation systems, highlighting how modern reconnaissance networks persist and adapt. As Black Lotus Labs stated, “JDY demonstrates how IoT/SOHO botnets and covert networks of compromised devices are being used for rapid vulnerability exploitation.”

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Crypto Campaign Challenges UK Bank Transfer Restrictions

Stand With Crypto UK is mobilizing 286,000 members to protest UK bank restrictions on...

Mastercard Launches AI Payment Platform for Machine Transactions

Mastercard launched Agent Pay for Machines, a new platform enabling AI agents to autonomously...

Metaplanet Considers Share Buyback Amid Low Bitcoin NAV

Metaplanet's CEO says the company will strongly consider buying back its own shares as...

Prediction Markets Overtake Onchain Gambling in Q1 2026

TRM Labs data shows prediction markets surged to $36.6B in Q1 2026, overtaking onchain...

TD Cowen Hikes Google Stock Target to $475, Reiterates Buy

Investment bank TD Cowen reaffirmed its buy rating and increased the 12-month price target...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading