Cybersecurity researchers at Lumen’s Black Lotus Labs have identified a significant expansion of the JDY botnet, a covert network linked to China-nexus state-sponsored threat actors. The botnet now comprises over 1,500 compromised small office/home office (SOHO) and IoT devices, up from 650 bots in January 2024. JDY operates as a centrally controlled, high-performance scanner used for targeted reconnaissance and service fingerprinting, feeding structured data into a larger scanning ecosystem for follow-on exploitation.
Originally a cluster within the KV-botnet, JDY evolved after the U.S. government takedown of KV-botnet in early 2024. The botnet is suspected to be offered to various hacking outfits, including groups like Volt Typhoon, and is used to flag vulnerable infrastructure following public disclosures. Most compromised nodes are located in the U.S. and Brazil, with a diverse device makeup including Cisco, Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys products, many of which are end-of-life with known vulnerabilities.
The botnet’s architecture uses Tor nodes for management, with command-and-control (C2) servers directing bots to perform targeted scanning rather than indiscriminate probing. Attack chains exploit newly disclosed vulnerabilities in edge devices, such as CVE-2026-35616, to deliver a shell script dropper that downloads a primary payload based on processor architecture. The malware adapts its scanning methodology based on system privileges, using raw sockets for high-speed SYN scanning or standard TCP/TLS connections otherwise. This activity informs asset discovery and vulnerability-targeting pipelines for Chinese threat actors.
Black Lotus Labs emphasizes that JDY’s growth and adaptation demonstrate how modern reconnaissance networks persist despite takedowns, providing adversaries with timely targeting data within hours of vulnerability disclosure.
CVEs: CVE-2026-35616, CVE-2023-20118, CVE-2022-32548, CVE-2023-24738, CVE-2021-36260, CVE-2026-11645
Attack groups: Volt Typhoon
Malware: JDY botnet, KV-botnet
Companies: Lumen Technologies, Cisco, Araknis, Mimosa Networks, Ubiquiti Inc., DrayTek, Hikvision, Linksys
Products: Cisco RV320, Cisco RV325, Cisco RV042, DrayTek Vigor3900 Series, Araknis AN-300-RT-4L2W, Hikvision IP cameras, Linksys LRT224
Original source: thehackernews.com