BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Linked JDY Botnet Expands, Infects 1,500 Devices

Chinese state-linked JDY botnet grows, scans for vulnerabilities to exploit.

  • The JDY botnet, used by Chinese state-sponsored hacking groups like Volt Typhoon, has rapidly expanded to over 1,500 compromised SOHO routers and IoT devices.
  • Its operators have diversified their targets to include devices from Ubiquiti, Hikvision, Linksys, and others, primarily located in the U.S. and Brazil.
  • The network functions as a centralized, high-performance scanner for targeted reconnaissance, feeding data into a larger ecosystem for exploitation shortly after vulnerabilities are disclosed.

Cybersecurity researchers at Lumen’s Black Lotus Labs have documented a resurgence and expansion of the JDY botnet, a covert network linked to China-nexus state-sponsored actors. The findings, detailed in a report shared with The Hacker News, show its growth from 650 bots in January 2024 to more than 1,500 compromised devices today. This industrialized reconnaissance effort enables Chinese nation-state groups to rapidly identify vulnerable infrastructure following public disclosures.
Initially flagged within the KV-botnet cluster in late 2023, JDY evolved into an independent capability after the U.S. government’s takedown of KV-botnet in early 2024. Consequently, the botnet now serves as a conduit for feeding structured reconnaissance data into a larger scanning ecosystem. The malware’s architecture uses Tor nodes to manage command-and-control servers, which direct bots to perform targeted system profiling and scanning.
Moreover, the malware’s scanning methodology adapts based on its local privileges, using high-speed SYN scanning when root access is available. This activity informs downstream exploitation systems, highlighting how modern reconnaissance networks persist and adapt. As Black Lotus Labs stated, “JDY demonstrates how IoT/SOHO botnets and covert networks of compromised devices are being used for rapid vulnerability exploitation.”

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

CISOs Earn Strategic Influence by Enabling Fast, Visible AI Adoption

76% of employees now use AI at work, up from 55% the previous year,...

HTX rebuilds wallets after UK sanctions to evade compliance

TRM Labs reports HTX rebuilt its wallet infrastructure after UK sanctions, rapidly rotating wallets...

SpaceX IPO Blueprint: Buy AI Pop, Re-enter Post-Lockup

A financial commentator recommends buying the SpaceX IPO after hype fades and insider lockups...

Foundry asks Bitcoin miners to vote on BIP-110 support

Foundry USA, the world’s largest Bitcoin mining pool by hashrate, has begun soliciting votes...

Global sting takes down Kratos phishing kit, 200+ servers seized

German and US law enforcement shut down more than 200 servers powering the Kratos...

Must Read

10 Best Crypto to Mine Without Special Hardware Equipment

A lot of people mostly think that it takes a difficult process to mine cryptocurrency. today we are going to show you some of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading