BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Linked JDY Botnet Expands, Infects 1,500 Devices

Chinese state-linked JDY botnet grows, scans for vulnerabilities to exploit.

  • The JDY botnet, used by Chinese state-sponsored hacking groups like Volt Typhoon, has rapidly expanded to over 1,500 compromised SOHO routers and IoT devices.
  • Its operators have diversified their targets to include devices from Ubiquiti, Hikvision, Linksys, and others, primarily located in the U.S. and Brazil.
  • The network functions as a centralized, high-performance scanner for targeted reconnaissance, feeding data into a larger ecosystem for exploitation shortly after vulnerabilities are disclosed.

Cybersecurity researchers at Lumen’s Black Lotus Labs have documented a resurgence and expansion of the JDY botnet, a covert network linked to China-nexus state-sponsored actors. The findings, detailed in a report shared with The Hacker News, show its growth from 650 bots in January 2024 to more than 1,500 compromised devices today. This industrialized reconnaissance effort enables Chinese nation-state groups to rapidly identify vulnerable infrastructure following public disclosures.
Initially flagged within the KV-botnet cluster in late 2023, JDY evolved into an independent capability after the U.S. government’s takedown of KV-botnet in early 2024. Consequently, the botnet now serves as a conduit for feeding structured reconnaissance data into a larger scanning ecosystem. The malware’s architecture uses Tor nodes to manage command-and-control servers, which direct bots to perform targeted system profiling and scanning.
Moreover, the malware’s scanning methodology adapts based on its local privileges, using high-speed SYN scanning when root access is available. This activity informs downstream exploitation systems, highlighting how modern reconnaissance networks persist and adapt. As Black Lotus Labs stated, “JDY demonstrates how IoT/SOHO botnets and covert networks of compromised devices are being used for rapid vulnerability exploitation.”

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AMD stock jumps on expanded Microsoft Azure partnership

AMD stock surged 1.58% on July 20, gaining an additional 3.56% in pre-market trading...

Moreno: DOJ, not states, to enforce CLARITY Act ethics

The White House reportedly agreed to ethics language for the CLARITY Act, potentially clearing...

Bitcoin ETFs Hit Five-Day Inflow Streak, BTC Above $65K

US spot Bitcoin ETFs recorded $226.9 million in net inflows on Monday, their fifth...

ServiceNow AI flaw exploited in wild, patch now

Threat actors are actively exploiting CVE-2026-6875, a critical sandbox escape vulnerability in the ServiceNow...

Cardano ADA Surges 4.2% as Market Rebounds

Cardano (ADA) has rallied by 4.2% in the last 24 hours and 9.3% in...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading