news.mlab.sh
Back to the feed
threat-intel

China-linked JDY botnet expands targeting of U.S. military networks

High
Summary

A Chinese-linked botnet, JDY, has significantly expanded its targeting of U.S. military networks and associated infrastructure. The botnet, previously associated with Volt Typhoon, utilizes reconnaissance techniques like scanning and fingerprinting to identify vulnerable systems, often shortly after public vulnerability disclosures. This activity highlights a concerning trend of APT actors rapidly operationalizing reconnaissance data to exploit newly discovered flaws, posing a risk to critical infrastructure.

The JDY botnet, now comprising over 1,500 compromised SOHO and IoT devices, is primarily focused on the United States, with a particular emphasis on military and related networks. Researchers at Black Lotus Labs have observed its evolution from approximately 650 bots in January 2024, noting its unique approach as a distributed scanning and fingerprinting network rather than a traditional DDoS botnet. This allows operators to quickly identify vulnerable systems following public vulnerability disclosures, suggesting a direct operationalization of reconnaissance output by China-nexus APT actors. The botnet’s capabilities include service discovery, banner grabbing, TLS certificate collection, protocol fingerprinting, and flaw-focused reconnaissance, targeting a wide range of sectors including defense.

Read the full article at BleepingComputer