{"id":56206,"date":"2026-06-10T19:58:05","date_gmt":"2026-06-10T23:58:05","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=56206"},"modified":"2026-06-10T19:58:05","modified_gmt":"2026-06-10T23:58:05","slug":"jdy-botnet-cyber-reconnaissance","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/jdy-botnet-cyber-reconnaissance\/","title":{"rendered":"JDY Botnet Expands to 1,500 Devices for Cyber Reconnaissance"},"content":{"rendered":"<p>In a significant escalation of cyber reconnaissance capabilities, security researchers have documented the rapid expansion of the <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">JDY botnet<\/a>, a covert network of compromised devices linked to Chinese state-sponsored threat actors. The botnet, now comprising over 1,500 small office\/home office (SOHO) routers and Internet of Things (IoT) devices, has evolved from a supporting component of a larger malicious network into a standalone, high-performance scanning platform. This development signals a dangerous shift in how nation-state adversaries conduct persistent, large-scale intelligence gathering, transforming compromised consumer-grade hardware into a sophisticated tool for mapping global internet infrastructure and identifying exploitable vulnerabilities.<\/p>\n<h2>The Resurgence of JDY Following the KV-Botnet Takedown<\/h2>\n<p>JDY first came to the attention of the cybersecurity community in December 2023, when it was identified as a distinct operational cluster within the larger KV-botnet. The original KV-botnet, which had been used by Chinese hacking groups such as Volt Typhoon for broad, indiscriminate scanning of internet targets, was taken down by U.S. government action in early 2024. The takedown, however, did not eliminate the underlying capability. Instead, the operators adapted. Following the disruption, the second KV cluster largely went offline, but the JDY segment began demonstrating significant behavioral changes and a marked increase in activity. This transition from being a secondary component of a dismantled botnet to an independent and thriving operation underscores a critical lesson in modern cyber conflict: disrupting specific infrastructure does not neutralize the adversary&#8217;s intent or methodology.<\/p>\n<h2>Anatomy of a Modern Reconnaissance Botnet<\/h2>\n<p>The JDY botnet is not designed for direct data theft or ransomware deployment. Its primary function is far more strategic: continuous, high-volume reconnaissance. The network operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and map exposed services at scale. This structured reconnaissance data is then fed into a larger ecosystem, where it informs follow-on target identification and exploitation by Chinese nation-state groups. The architecture powering this operation is notably resilient. The operators utilize Tor nodes to manage their infected infrastructure, including both the command-and-control (C2) and payload servers. This layered approach\u2014using obfuscation layers on top of compromised devices\u2014makes the network exceptionally difficult to dismantle. The C2 servers do not direct the bots to engage in indiscriminate scanning; instead, they assign targeted reconnaissance and system profiling tasks, streamlining the intelligence-gathering process.<\/p>\n<h3>The Malware&#8217;s Sophisticated Scanning Engine<\/h3>\n<p>A key feature of the malware deployed on JDY bots is its adaptive scanning methodology. The malicious software is designed to fingerprint the host system, receive specific tasks from the central C2 server, and execute high-volume probing using multiple protocols including TCP, SSL, UDP, and ICMP. Critically, its behavior changes based on the privileges it holds on the compromised device. If the malware can open a raw socket\u2014an indication of root or administrative access\u2014it initiates high-speed SYN scanning using custom-crafted TCP packets. This method is significantly faster and harder to detect than standard application-layer scanning. If raw sockets are unavailable, or if the task is a web-specific scan, the engine seamlessly falls back to standard TCP and TLS connections, or employs protocols like UDP and ICMP. This level of technical sophistication allows the botnet to operate effectively across a diverse range of compromised hardware, each with different performance capabilities and security configurations. The results of these scans, including captured TLS certificates, metadata, and service fingerprints, are reported back to a central dispatch server for processing and analysis.<\/p>\n<h2>From 650 to 1,500 Devices: A Dramatic Expansion<\/h2>\n<p>The growth of the JDY botnet is one of its most alarming characteristics. From roughly 650 active bots at the beginning of January 2024, the network has more than doubled, now exceeding 1,500 compromised devices. This surge points to an active and successful campaign to infect vulnerable hardware. The geographic distribution of these infected nodes is strategic, with the largest concentration found in the United States and <a href=\"https:\/\/overcentral.com\/en\/cadillac-opens-experience-centers-brazil-f1-gp\/\" title=\"Cadillac Opens Three Experience Centers in Brazil Ahead of F1 GP\" data-iacss-internal=\"1\">Brazil<\/a>, followed by devices across Europe and Asia. The diversity of the targeted devices has also expanded dramatically. Initially, the cluster primarily featured Cisco RV320 and RV325 routers. Today, the botnet includes a much broader range of hardware from manufacturers such as Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys. This diversification provides the operators with a larger and more resilient pool of resources.<\/p>\n<h3>Strategic Advantage of SOHO and IoT Devices<\/h3>\n<p>Using compromised SOHO routers and IoT devices offers a distinct strategic advantage for the botnet operators. These devices are typically less monitored than enterprise-grade servers and are often deployed behind residential or small business internet connections. &#8220;The botnet&#8217;s large number of U.S.-based SOHO\/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists,&#8221; Black Lotus Labs noted. By distributing their scanning and reconnaissance activity across a wide range of geographically distributed IP addresses, the operators make it far less likely that any single IP will be flagged as a scanner and blocked. Furthermore, the traffic generated by the botnet blends in naturally with legitimate user traffic from thousands of normal homes and small offices, making network-based detection extremely difficult.<\/p>\n<h2>Industrialized Reconnaissance for Chinese State-Sponsored Groups<\/h2>\n<p>The activity of the JDY botnet is not random or opportunistic; it is a highly organized and industrialized effort. The scanning and service fingerprinting conducted by the botnet is specifically aimed at flagging vulnerable infrastructure, often in direct response to public vulnerability disclosures. When a new critical vulnerability is announced, such as the hypothetical CVE-2026-35616 used in some attack chains, the JDY botnet can be rapidly tasked to scan the internet for exposed, unpatched devices. This near-real-time reconnaissance capability provides Chinese threat actors with an unparalleled advantage. The attack chains used by the malware to infect new devices are efficient. They weaponize newly disclosed vulnerabilities in edge devices to deliver a shell script dropper. This dropper checks if the malware is already active on the device; if not, it downloads the primary payload, which is specifically compiled for the detected processor architecture (e.g., mips, mips64, mipsel). <a href=\"https:\/\/overcentral.com\/en\/windows-11-shared-audio-two-headsets\/\" title=\"Windows 11 Finally Adds Shared Audio for Two Bluetooth Headsets at Once\" data-iacss-internal=\"1\">Once<\/a> the malware is launched and running in memory, it is deleted from disk, leaving minimal forensic evidence.<\/p>\n<h2>The Future of Persistence: Adapting After Disruption<\/h2>\n<p>The evolution of the JDY botnet from a component of the KV-botnet to an independent, high-performance reconnaissance platform provides a stark warning about the nature of modern cyber threats. The takedown of the KV-botnet demonstrated that while specific infrastructure can be disrupted, the underlying capability and the team behind it can persist and adapt. JDY&#8217;s continued operation illustrates how modern reconnaissance networks are not static; they evolve, diversify, and become more resilient. &#8220;JDY&#8217;s growth and continued operation illustrate how modern reconnaissance networks persist despite takedowns and adapt as a durable capability within a broader adversary ecosystem,&#8221; the researchers concluded. The most significant takeaway for network defenders is that vulnerability scanning and reconnaissance are no longer just the first steps of an attack; they are a persistent, industrialized activity powered by a vast, adaptive, and increasingly diverse network of compromised devices. The JDY botnet represents a new standard in how nation-state adversaries maintain a continuous, stealthy presence on the global internet, mapping the digital terrain and waiting for the next opportunity to strike.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a significant escalation of cyber reconnaissance capabilities, security researchers have documented the rapid expansion of the JDY botnet, a covert network of compromised devices linked to Chinese state-sponsored threat actors. The botnet, now comprising over 1,500 small office\/home office (SOHO) routers and Internet of Things (IoT) devices, has evolved from a supporting component of [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84546,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/56206.png","fifu_image_alt":"JDY Botnet Expands to 1,500 Devices for Cyber Reconnaissance","footnotes":""},"categories":[2],"tags":[],"class_list":["post-56206","post","type-post","status-publish","format-standard","has-post-thumbnail","category-videogames"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/56206.png","fifu_image_alt":"JDY Botnet Expands to 1,500 Devices for Cyber Reconnaissance","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/56206","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=56206"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/56206\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84546"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=56206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=56206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=56206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}