news.mlab.sh
Back to the feed
threat-intel

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

High
Summary

A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-scale reconnaissance, scanning infrastructure for vulnerabilities and mapping exposed services. This expansion highlights the persistent threat posed by state-sponsored actors utilizing compromised IoT devices to conduct industrial espionage and potentially pave the way for future attacks.

The JDY botnet, identified by Lumen’s Black Lotus Labs, has undergone a substantial expansion, growing from 650 devices in early January 2024 to over 1,500. This growth is attributed to the botnet’s use as a covert reconnaissance tool, primarily targeting infrastructure for vulnerabilities. The botnet’s architecture utilizes Tor nodes for command and control, allowing operators to manage a distributed network of compromised SOHO routers, firewalls, and IoT devices. This approach enables the JDY botnet to evade traditional security measures like geofencing and IP reputation-based detection, making it difficult to track and block. The botnet’s operators are suspected of offering access to hacking groups, furthering its reach and capabilities.

The JDY botnet’s scanning methodology is sophisticated, adapting to the privileges of the compromised devices. It leverages newly disclosed vulnerabilities, such as CVE-2026-35616, to deliver a shell script dropper and employs techniques like SYN scanning and protocol-specific probing (TCP, SSL, UDP, ICMP) to gather detailed information about targeted systems. This data is then relayed to central servers for ongoing intelligence gathering, supporting Chinese nation-state objectives. The botnet’s diverse range of infected devices – including Cisco, Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys – further amplifies its potential impact, particularly in the U.S. and Brazil, where the majority of the compromised nodes are located.

Read the full article at The Hacker News