Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    FBI disrupts massive AI-powered phishing service using a million URLs

    June 14, 2026

    Ex-school district employee jailed for hacks on former employer

    June 13, 2026

    Scientists Discover Vast Ancient ‘Necropolis’ Teeming With Strange New Creatures

    June 13, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»China-linked JDY botnet expands targeting of U.S. military networks
    News

    China-linked JDY botnet expands targeting of U.S. military networks

    adminBy adminJune 10, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    China

    The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts.

    According to researchers at Black Lotus Labs by Lumen, who have been monitoring its activity, JDY maintains a strong focus on the United States, where many of its compromised devices are located and where it heavily targets military and associated networks.

    The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.

    image

    While the numbers seem low, it’s important to note that JDY isn’t an exploitation framework or a DDoS botnet that requires large swarms to accumulate firepower, but is instead a distributed scanning and fingerprinting network that helps its operators locate targets vulnerable to newly disclosed flaws.

    “Analysis of this activity shows a clear focus on identifying vulnerable infrastructure shortly after public vulnerability disclosures, suggesting that reconnaissance output is rapidly operationalized by China-nexus advanced persistent threat (APT) actors,” reads the Black Lotus Labs report.

    “This targeted focus has been observed across a range of sectors, with the U.S. military and associated entities as the most prominent.”

    Most impacted countries by the JDY botnet
    Most impacted countries by the JDY botnet
    Source: Black Lotus Labs

    CISA has previously warned about the risk Volt Typhoon operatives pose to unprotected SOHO routers, urging network device vendors to eliminate vulnerabilities in SOHO router web management interfaces (WMIs) during the design and development phases.

    The JDY botnet is designed to conduct service discovery, service banner grabbing, TLS certificate collection, protocol fingerprinting, and flaw-focused reconnaissance.

    Among the compromised devices are those from Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, for MIPS, MIPS64, MIPSEL, and MIPSEL64 architectures.

    The threat actors are quick to target newly disclosed vulnerabilities, with Lumen researchers observing JDY scans targeting CVE-2026-35616 shortly after Fortinet publicly disclosed the FortiClient EMS flaw.

    JDY targeting volume on a specific date
    JDY targeting volume on a specific date
    Source: Black Lotus Labs

    The operators control the botnet through hidden Tor services, which also serve as command-and-control (C2) infrastructure. The open-source reverse-shell and host-management framework Platypus is also used in some cases.

    JDY network overview
    JDY network overview
    Source: Black Lotus Labs

    The malware registers with a central “Dispatch Service” and receives scanning assignments, which it executes, compresses the results, and sends them back to the C2.

    The scanning module supports the following:

    • TCP scanning
    • SSL/TLS scanning
    • UDP scanning
    • ICMP probing
    • Banner collection
    • TLS certificate harvesting
    • Service fingerprinting using downloadable rule sets

    The botnet client repeats the same cycle until the operator specifically orders it to stop.

    The TCP scanning function is one of the most technically interesting, say the researchers, explaining that, when JDY has sufficient privileges, it performs much faster and stealthier raw SYN scanning.

    “If the malware can open a raw socket, which generally requires root or administrative privileges, it initiates high-speed SYN scanning using custom-crafted TCP packets,” explains the report.

    “These custom packets use a fixed source port of 19000, increment the destination ports one at a time, and batch-process thousands of scan targets.”

    Code snippet handling the raw SYN scanning
    Code snippet handling the raw SYN scanning
    Source: Black Lotus Labs

    As JDY botnet activity increases, organizations should ensure routers, firewalls, and IoT devices are running the latest security updates and patches to prevent them from being recruited into reconnaissance networks.

    Defenders should also reduce their external attack surface by disabling unnecessary internet-exposed administrative interfaces, restricting remote management access, replacing default credentials, and monitoring for unusual outbound scanning activity originating from edge devices.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCVE-2026-46497 | THREATINT
    Next Article ZDI-26-353: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
    admin
    • Website

    Related Posts

    News

    FBI disrupts massive AI-powered phishing service using a million URLs

    June 14, 2026
    News

    Ex-school district employee jailed for hacks on former employer

    June 13, 2026
    News

    Scientists Discover Vast Ancient ‘Necropolis’ Teeming With Strange New Creatures

    June 13, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Our Picks

    FBI disrupts massive AI-powered phishing service using a million URLs

    June 14, 2026

    Ex-school district employee jailed for hacks on former employer

    June 13, 2026

    Scientists Discover Vast Ancient ‘Necropolis’ Teeming With Strange New Creatures

    June 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.