China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

A “resurgence and expansion” of JDY, a clandestine network connected to state-sponsored threat actors with ties to China, has alarmed cybersecurity specialists.

In a report shared with The Hacker News, Lumen’s Black Lotus Labs stated that the JDY botnet, which consists of more than 1,500 SOHO [small office and home office] and IoT devices, functions as a centrally controlled, high-performance scanner used to find, fingerprint, and continuously map exposed services at scale.

In mid-December 2023, JDY was initially identified as a cluster inside another botnet known as KV-botnet. Chinese hacker organizations such as Volt Typhoon have exploited the covert network, which consists of compromised SOHO routers, firewalls, and IoT devices, primarily for wider scanning against internet targets.

The botnet operators started altering the network’s behavior when the U.S. government took down KV-botnet in early 2024 read more about China-Linked JDY Botnet Expands to 1500+ Devices for Cyber Reconnaissance.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *