JDY Botnet Grows to 1,500 Devices for Rapid Vulnerability Mapping
ID: f4ac2198-1650-5268-9e68-0ae93f27e177
STIX ID: report--f4ac2198-1650-5268-9e68-0ae93f27e177
Feed Name: ThreatCluster
The JDY botnet — attributed to Chinese state-linked actors including Volt Typhoon — has expanded to over 1,500 compromised SOHO and IoT devices and conducts high-speed reconnaissance by scanning for newly disclosed vulnerabilities within hours, collecting banners, certificates, and metadata via Tor-based C2 to feed targeting data to state hackers; this evolution from the KV-botnet increases risk to exposed edge infrastructure (routers, firewalls, VPNs, cameras) and complicates traditional IP-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
