logo

JDY Botnet Grows to 1,500 Devices for Rapid Vulnerability Mapping

ID: f4ac2198-1650-5268-9e68-0ae93f27e177

STIX ID: report--f4ac2198-1650-5268-9e68-0ae93f27e177

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-10

Date Updated: 2026-06-11

...
...

The JDY botnet — attributed to Chinese state-linked actors including Volt Typhoon — has expanded to over 1,500 compromised SOHO and IoT devices and conducts high-speed reconnaissance by scanning for newly disclosed vulnerabilities within hours, collecting banners, certificates, and metadata via Tor-based C2 to feed targeting data to state hackers; this evolution from the KV-botnet increases risk to exposed edge infrastructure (routers, firewalls, VPNs, cameras) and complicates traditional IP-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.