JDY Botnet Evolves After KV Takedown, Targets Military Networks
ID: 2da29a15-82df-5341-8490-78cb344c99fc
STIX ID: report--2da29a15-82df-5341-8490-78cb344c99fc
Feed Name: Security Affairs
Threat Score
The JDY botnet — an IoT/SOHO-based reconnaissance network linked to Chinese state-sponsored groups — has reconstituted to over 1,500 devices and is performing stealthy, high-volume, adaptive scanning (via Tor C2 and transient payloads) to map exposed services and rapidly hunt for newly disclosed vulnerabilities (e.g., CVE-2026-35616), with the largest share of targets belonging to U.S. military and affiliated networks, supplying structured intelligence for follow-on exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
