China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
A "resurgence and expansion" of JDY, a clandestine network connected to state-sponsored threat actors with ties to China, has alarmed cybersecurity specialists.
In a report shared with The Hacker News, Lumen's Black Lotus Labs stated that the JDY botnet, which consists of more than 1,500 SOHO [small office and home office] and IoT devices, functions as a centrally controlled, high-performance scanner used to find, fingerprint, and continuously map exposed services at scale.
In mid-December 2023, JDY was initially identified as a cluster inside another botnet known as KV-botnet. Chinese hacker organizations such as Volt Typhoon have exploited the covert network, which consists of compromised SOHO routers, firewalls, and IoT devices, primarily for wider scanning against internet targe...

