Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Home/Threats/China-Linked JDY Botnet Exploits SOHO, IoT Devices
Threats

China-Linked JDY Botnet Exploits SOHO, IoT Devices

Key Takeaways The China-linked JDY botnet, a sophisticated reconnaissance tool, has significantly expanded its reach, now compromising over 1,500 SOHO and IoT devices globally. This botnet...

Emy Elsamnoudy
Emy Elsamnoudy
June 11, 2026 5 Min Read
50 0

Key Takeaways

  • The China-linked JDY botnet, a sophisticated reconnaissance tool, has significantly expanded its reach, now compromising over 1,500 SOHO and IoT devices globally.
  • This botnet specializes in rapidly scanning the internet for newly disclosed vulnerabilities, providing intelligence to Chinese state-backed threat actors like Volt Typhoon before patches can be widely applied.
  • JDY targets a broad spectrum of devices from major manufacturers, including Cisco, Ubiquiti, and Fortinet, with a primary focus on U.S. military-affiliated networks.
  • Despite previous disruption efforts against its companion KV-botnet, JDY has demonstrated resilience and a doubled operational capacity, highlighting the need for enhanced, adaptive defense strategies.

China-Linked JDY Botnet Surges, Exploiting SOHO and IoT Devices for Reconnaissance

A sophisticated botnet known as JDY, with clear ties to Chinese state-sponsored cyber operations, has re-emerged as a formidable reconnaissance asset, now controlling over 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices. These devices, distributed across North America, Europe, and Asia, are being leveraged not for direct attacks, but to meticulously scan the global internet for vulnerable systems, feeding critical intelligence back to China-affiliated hacking groups.

Table Of Content

  • Key Takeaways
  • China-Linked JDY Botnet Surges, Exploiting SOHO and IoT Devices for Reconnaissance
  • JDY’s Rapid Expansion and Evolving Threat Landscape
  • Operational Mechanics of the JDY Botnet
  • What You Should Do

The origins of the JDY botnet date back to late 2023, when it was initially identified as a component of the larger KV-botnet operation. This covert network was instrumental for China-backed entities, particularly the notorious Volt Typhoon group, in their espionage efforts targeting critical infrastructure within the United States. Following U.S. government actions to dismantle the KV cluster, JDY experienced a temporary dip, operating with approximately 650 active bots in January 2024. However, it has since quietly rebuilt and more than doubled its operational capacity, demonstrating significant resilience and adaptability.

JDY’s Rapid Expansion and Evolving Threat Landscape

Analysts at Lumen’s Black Lotus Labs have closely monitored JDY’s evolution, noting not only its growth but also a marked increase in its threat potential. According to a report shared with Cyber Security News (CSN), Lumen highlighted that the JDY botnet now targets a significantly broader array of devices. Manufacturers whose products are being exploited include Cisco, Ubiquiti, Hikvision, Draytek, Linksys, Araknis, and Mimosa Networks, underscoring the botnet’s versatile targeting capabilities.

One of JDY’s most alarming characteristics is its rapid response to new intelligence. Researchers have observed that botnet operators almost immediately shift their scanning activities to target newly disclosed vulnerabilities. For instance, a surge in scans against Fortinet devices was detected merely hours after the public disclosure of CVE-2026-35616. This swift action allows threat actors to pinpoint vulnerable systems and exploit them before organizations can implement necessary patches, giving them a critical advantage.

The majority of devices compromised by JDY are located in the United States, with a particular emphasis on scanning networks associated with U.S. military entities. Since the infected devices are typically ordinary residential and small business routers, their network traffic seamlessly blends with legitimate internet activity, making detection challenging for conventional security tools.

Operational Mechanics of the JDY Botnet

The JDY botnet operates through a meticulously structured system designed to maintain operator anonymity while ensuring the continuous activity of its compromised bots. Infected devices receive their scanning instructions from a command-and-control (C2) server, which communicates through hidden Tor nodes, effectively obscuring the identities of the operators. These bots then conduct multiprotocol scans across TCP, UDP, SSL, and ICMP channels, transmitting the compressed and encrypted results back to the central server.

The malware itself is designed to run on Linux-based systems, specifically targeting MIPS and MIPSEL processor architectures, which are prevalent in consumer-grade routers and edge network devices. The infection process is handled by a lightweight bash dropper. This dropper identifies the device’s processor type, downloads the corresponding payload, executes it, and then promptly deletes the executable file from the disk to minimize forensic traces. In some instances, devices are also managed via Platypus, an open-source remote shell tool, with the payload server located at 149.248.3[.]38 hosting a Platypus instance on port 13339.

By distributing scanning tasks across thousands of devices, each with a unique IP address, the JDY botnet effectively bypasses traditional defensive measures such as blocklists and geofencing. Each compromised device handles only a small portion of the overall scanning load, preventing any single IP address from generating sufficient anomalous activity to trigger alarms and get blocked. This distributed approach makes it exceedingly difficult for defenders to detect and neutralize the botnet’s reconnaissance efforts. An overview of how JDY distributes scanning across residential and small enterprise IP space illustrates this stealthy operational model.

What You Should Do

Lumen’s Black Lotus Labs researchers underscore that merely disrupting individual components of a botnet like JDY is insufficient. As demonstrated by its recovery and expansion after the KV cluster takedown, this capability adapts, rebuilds, and continues to supply intelligence to threat actors, often within hours of new vulnerability disclosures. To effectively counter such sophisticated and resilient threats, organizations must adopt a proactive and multi-layered defense strategy:

  • Implement CISA and NCSC Guidance: Adhere to the cybersecurity advisories from CISA and the UK National Cyber Security Centre (NCSC) specifically tailored for mitigating Volt Typhoon activity and defending against China-linked covert networks.
  • Adopt SASE Solutions: Consider deploying Secure Access Service Edge (SASE) solutions to minimize your organization’s internet-facing attack surface.
  • Regular Device Management: For all routers, firewalls, and IoT devices, ensure regular reboots, prompt application of security patches, and consistent software updates.
  • Move Beyond Static Defenses: Recognize that relying solely on IP reputation checks or static blocklists is no longer adequate against adversaries controlling thousands of legitimate-looking IP addresses. Implement dynamic threat intelligence and behavioral analytics.
  • Monitor for IoCs: Actively monitor your network for the following Indicators of Compromise (IoCs) associated with the JDY botnet:
    • IP Address: 149.248.3[.]38 (JDY botnet payload server hosting Platypus remote shell on port 13339)
    • Port: 13339 (Default port used by Platypus server for agent downloads)
    • AES Key: 0000000000000000bdb718bdf47cbcde (Hardcoded AES decryption key for C2 tasking responses)
    • Malware Version: 1.8.3.9 (Hardcoded version string in analyzed JDY malware samples)
    • Process Name: auditdy (Variable process name used by JDY dropper)
    • File Path: /etc/ or /tmp/ (Directories where JDY payload is written before execution)
    • Architecture: mips, mips64, mipsel, mipsel64 (Target processor architectures)
    • CVE: CVE-2026-35616 (Fortinet vulnerability exploited by JDY)
    • Network Path: /dispatch_service/v2/probe_status (C2 endpoint for initial check-in beacon via HTTPS POST)
    • Network Path: /data/v2/pscan (C2 endpoint for delivering compressed scan results with filename attr.json)
    • ICMP Identifier: 19037 (Hardcoded ICMP packet identifier in UDP/ICMP scanning for port 80)
    • Source Port: 19000 (Fixed source port used in high-speed SYN scanning mode)

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitHackerMalwarePatchSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Microsoft Exchange Server 0-Day Vulnerability Exploited in Attacks

Next Post

Attackers Abuse AWS CloudTrail, Google Cloud Logging to Evade Detection

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us