A significant resurgence of the JDY botnet, a covert reconnaissance network linked to China-nexus threat groups such as Volt Typhoon.
Originally part of the larger KV-botnet ecosystem that was heavily disrupted by U.S. government takedowns in early 2024, the JDY cluster managed to survive.
Today, it operates as a highly efficient operational relay box (ORB) network. Its primary purpose is to scan, fingerprint, and map exposed services across the internet.
By identifying vulnerable systems, this botnet feeds structured reconnaissance data into a larger threat ecosystem, giving advanced persistent threat (APT) actors the exact targets they need for immediate exploitation.
JDY Botnet Targets Flaws
Since its lowest point in January 2024, the JDY botnet has more than doubled in size, now controlling over 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices.
In the past, the network relied almost entirely on a few vulnerable Cisco router models. Now, it has diversified its victim base to include equipment from manufacturers like Ubiquiti, Hikvision, Linksys, Araknis, and Draytek.

What makes this expansion particularly dangerous is the geographic distribution of the infected devices.
Because the vast majority are physically located in the United States, operators can easily bypass traditional security defenses like geofencing and static blocklists.
By hiding their malicious scanning within normal residential and small business internet traffic, the attackers prevent any single IP address from being flagged as a threat.

Rather than unthinkingly scanning the entire web, the JDY botnet conducts highly targeted intelligence gathering.
For example, researchers observed a sharp spike in scans targeting Fortinet equipment just hours after a new vulnerability (CVE-2026-35616) was publicly disclosed.
This proves the operators are specifically hunting for vulnerable infrastructure before organizations have time to apply patches.

According to Lumen research, the malware retrieves dynamic tasks from its dispatch service. The scanning engine is highly adaptive and chooses its methods based on the permissions it holds on the infected device.
If it has root access, it uses high-speed, raw-packet scanning to quietly discover open ports without triggering application-level logging.
If it lacks administrative rights, it falls back to standard TCP and TLS connections to gather detailed application banners, domain resolutions, and security certificates.
The malware even uses custom fingerprinting rules to identify specific services, such as Oracle WebLogic. All this data is compressed, encrypted, and sent back to the attackers as a structured JSON file.
To defend against covert networks like JDY, organizations must recognize that simple IP-based reputation tools are no longer enough.
Enterprise security teams should adopt solutions such as Secure Access Service Edge (SASE) to reduce their external attack surface.
Basic hygiene is equally critical: regularly reboot routers to clear memory-resident threats, and apply firmware updates immediately.
Finally, following defense guidance from agencies like CISA and the U.K. NCSC is essential to protecting your infrastructure from these fast-moving, state-sponsored campaigns.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.