DKDKCISSPSearch
Threat Research

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

Cybersecurity researchers have warned of a of JDY , a covert network associated with China-nexus state-sponsored threat actors.

DKCISSP News DeskThe Hacker News7 Oct 2026, 8:28 pm
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Cybersecurity researchers have warned of a "resurgence and expansion" of JDY , a covert network associated with China-nexus state-sponsored threat actors.

The latest findings from Black Lotus Labs show that the malware has expanded in scope to infect a broader range of devices and act as a conduit to feed "structured reconnaissance data" into a larger scanning ecosystem for follow-on target identification and exploitation.

Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited - DrayTek Vigor3900 Series - Possibly vulnerable to flaws like CVE-2022-32548 Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like CVE-2023-24738 Hikvision IP cameras - Possibly vulnerable to flaws like CVE-2021-36260 Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web "The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.

Black Lotus Labs told The Hacker News that the cluster in Brazil is reflective of the fact that "we're seeing more and more botnets made up of Brazilian victims these days." Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.

Primarily used for broader scanning against internet targets, the stealthy network comprising compromised SOHO routers, firewalls, and IoT devices has been put to use by Chinese hacking groups like Volt Typhoon.

It's suspected that the botnet is offered by the operators to various hacking outfits, while carrying out reconnaissance and targeting on their own.

A noteworthy functionality of the malware is its ability to adapt its scanning methodology based on its privileges on the local system.

The vast majority of the victim devices are assessed to have reached end-of-life (EoL) with known vulnerabilities.

Attack chains weaponize newly disclosed vulnerabilities in edge devices (e.g., CVE-2026-35616) to deliver a shell script dropper that checks if the malware is already active, and if not, proceeds to download the primary payload based on the detected processor architecture (e.g., mips, mips64, mipsel, or mipsel64).

The malware that facilitates scanning and target reconnaissance is designed to fingerprint the host, receive scanning tasks from a central C2 server, carry out high-volume TCP, SSL, UDP, and ICMP-assisted probing, capture responses (TLS certificates, metadata, etc.), and report the results back to the dispatch server.

What happened

Cybersecurity researchers have warned of a "resurgence and expansion" of JDY , a covert network associated with China-nexus state-sponsored threat actors.

The latest findings from Black Lotus Labs show that the malware has expanded in scope to infect a broader range of devices and act as a conduit to feed "structured reconnaissance data" into a larger scanning ecosystem for follow-on target identification and exploitation.

What changed

Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited - DrayTek Vigor3900 Series - Possibly vulnerable to flaws like CVE-2022-32548 Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like CVE-2023-24738 Hikvision IP cameras - Possibly vulnerable to flaws like CVE-2021-36260 Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web "The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.

Black Lotus Labs told The Hacker News that the cluster in Brazil is reflective of the fact that "we're seeing more and more botnets made up of Brazilian victims these days." Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.

Who is affected

Primarily used for broader scanning against internet targets, the stealthy network comprising compromised SOHO routers, firewalls, and IoT devices has been put to use by Chinese hacking groups like Volt Typhoon.

It's suspected that the botnet is offered by the operators to various hacking outfits, while carrying out reconnaissance and targeting on their own.

Why it matters

A noteworthy functionality of the malware is its ability to adapt its scanning methodology based on its privileges on the local system.

The vast majority of the victim devices are assessed to have reached end-of-life (EoL) with known vulnerabilities.

Technical details

Attack chains weaponize newly disclosed vulnerabilities in edge devices (e.g., CVE-2026-35616) to deliver a shell script dropper that checks if the malware is already active, and if not, proceeds to download the primary payload based on the detected processor architecture (e.g., mips, mips64, mipsel, or mipsel64).

The malware that facilitates scanning and target reconnaissance is designed to fingerprint the host, receive scanning tasks from a central C2 server, carry out high-volume TCP, SSL, UDP, and ICMP-assisted probing, capture responses (TLS certificates, metadata, etc.), and report the results back to the dispatch server.

Specifically, the JDY cluster is being used to conduct targeted scanning and service fingerprinting with an aim to flag vulnerable infrastructure following public disclosures.

Response

The capability persists, adapts, and continues to provide adversaries with timely targeting data, often within hours of vulnerability disclosure." (The story was updated after publication to include more insights from Lumen Black Lotus Labs.)

What remains unknown

Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited - DrayTek Vigor3900 Series - Possibly vulnerable to flaws like CVE-2022-32548 Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like CVE-2023-24738 Hikvision IP cameras - Possibly vulnerable to flaws like CVE-2021-36260 Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web "The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.

Attribution

The Hacker News: Cybersecurity researchers have warned of a "resurgence and expansion" of JDY , a covert network associated with China-nexus state-sponsored threat actors.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN THREAT RESEARCH

More cybersecurity reporting

Microsoft Outlook to block MSIX attachments starting NovemberBleepingComputer · 7 Oct 2026, 9:14 pmHalf of Cybersecurity Pros Still Rely on Passwords Despite Security CoInfosecurity Magazine · 7 Oct 2026, 3:45 pmLinux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and TaiwanThe Hacker News · 6 Oct 2026, 11:54 pmIncident affecting ASOS customersNCSC-UK · 6 Oct 2026, 10:18 pm