logo

JDY Botnet Evolves After KV Takedown, Targets Military Networks

ID: 2da29a15-82df-5341-8490-78cb344c99fc

STIX ID: report--2da29a15-82df-5341-8490-78cb344c99fc

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Pierluigi Paganini

...
...

The JDY botnet — an IoT/SOHO-based reconnaissance network linked to Chinese state-sponsored groups — has reconstituted to over 1,500 devices and is performing stealthy, high-volume, adaptive scanning (via Tor C2 and transient payloads) to map exposed services and rapidly hunt for newly disclosed vulnerabilities (e.g., CVE-2026-35616), with the largest share of targets belonging to U.S. military and affiliated networks, supplying structured intelligence for follow-on exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.