Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked JDY Botnet Expands to Over 1,500 Devices

China-Linked JDY Botnet Expands to Over 1,500 Devices

Posted on June 13, 2026 By CWS

Experts in cybersecurity have raised alarms over the significant growth and resurgence of the JDY botnet, a network linked to Chinese state-sponsored cyber groups. The botnet, which now includes over 1,500 compromised devices, is used for extensive scanning and reconnaissance operations.

Expansion of JDY Botnet

According to Black Lotus Labs of Lumen Technologies, the JDY network predominantly comprises compromised small office/home office (SOHO) and Internet of Things (IoT) devices. This botnet is employed to identify and map out vulnerable internet services on a large scale. Initially detected as part of another botnet known as KV-botnet in December 2023, JDY has since evolved into a formidable threat utilized by Chinese hacking entities like Volt Typhoon.

Following the U.S. government’s dismantling of the KV-botnet in early 2024, operators of the JDY botnet adjusted their tactics, leading to the shutdown of a significant portion of the KV-botnet. The JDY network has not only expanded its scope but also diversified the types of devices it infects, integrating into a broader cyber reconnaissance ecosystem.

Targeted Scanning and Reconnaissance

The JDY botnet is strategically used for targeted scanning and service identification, aiming to exploit vulnerabilities in infrastructure following public vulnerability disclosures. This points to a sophisticated and industrial-level reconnaissance effort by Chinese nation-state actors. Black Lotus Labs reports that the size of the JDY botnet has more than doubled from 650 bots in January 2024 to over 1,500 today, with the majority of compromised devices located in the United States and Brazil, followed by regions in Europe and Asia.

Devices previously dominated by Cisco routers have now diversified to include technology from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys. Many of these devices are outdated with known vulnerabilities, making them prime targets for exploitation.

Technical Insights and Future Implications

The architecture of the JDY botnet is complex, utilizing Tor nodes for controlling compromised infrastructures, including command-and-control (C2) and payload servers. This setup allows for precise reconnaissance and system profiling, rather than indiscriminate scanning, with data sent to central servers for intelligence gathering.

The malware used in the JDY botnet is designed to adapt its scanning techniques based on local system privileges, optimizing its efficacy in discovering vulnerabilities. This capability indicates a sophisticated approach to asset discovery and vulnerability targeting, vital for subsequent exploitation and attack orchestration.

Black Lotus Labs highlights that the JDY botnet exemplifies how IoT and SOHO botnets are employed for rapid exploitation of vulnerabilities. Despite efforts to dismantle such networks, their resilience and adaptability allow them to persist and provide adversaries with up-to-date targeting data shortly after vulnerabilities are disclosed.

The ongoing evolution of the JDY botnet demonstrates that while individual nodes may be disrupted, the overarching capability remains intact, continuing to serve adversarial objectives efficiently and effectively.

The Hacker News Tags:Black Lotus Labs, China, cyber reconnaissance, cyber threats, Cybersecurity, hacking groups, IoT devices, JDY botnet, SOHO routers, Vulnerabilities

Post navigation

Previous Post: GitHub to Restrict npm Scripts by Default to Enhance Security
Next Post: GitHub’s NPM 12 Blocks Script Execution to Enhance Security

Related Posts

Securing CI/CD workflows with Wazuh Securing CI/CD workflows with Wazuh The Hacker News
AI Becomes Russia’s New Cyber Weapon in War on Ukraine AI Becomes Russia’s New Cyber Weapon in War on Ukraine The Hacker News
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks The Hacker News
Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive The Hacker News
DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM DOJ Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of CSAM The Hacker News
Anthropic Introduces Claude Code Security for AI Vulnerability Scanning Anthropic Introduces Claude Code Security for AI Vulnerability Scanning The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Langflow Security Flaw Enables Unauthenticated Access
  • Agentjacking Exploits AI Tools to Execute Malicious Code
  • Ivanti, Fortinet, SAP Address Critical Security Flaws
  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Langflow Security Flaw Enables Unauthenticated Access
  • Agentjacking Exploits AI Tools to Execute Malicious Code
  • Ivanti, Fortinet, SAP Address Critical Security Flaws
  • GitHub’s NPM 12 Blocks Script Execution to Enhance Security
  • China-Linked JDY Botnet Expands to Over 1,500 Devices

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark