logo

JDY Botnet Resurges: China-Nexus IoT Army Hunts New Vulnerabilities Within Hours

ID: 240b5e51-6db1-569e-b858-859c34c0df5f

STIX ID: report--240b5e51-6db1-569e-b858-859c34c0df5f

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Do Son

...
...

The report describes a renewed and expanded JDY botnet—linked to Chinese state-backed actors—now exceeding 1,500 compromised routers and IoT devices across multiple vendors and geographies. The botnet operates as a fast, distributed reconnaissance platform (using Tor, encrypted tasking, adaptive fingerprinting and SYN/TCP scans) that rapidly probes newly disclosed vulnerabilities (e.g., CVE-2026-35616) to harvest targeting data, with a primary focus on military-related networks; defenders are urged to patch edge devices, replace end-of-life routers, and consult the full Black Lotus Labs analysis for indicators and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.