JDY Botnet Resurges: China-Nexus IoT Army Hunts New Vulnerabilities Within Hours
ID: 240b5e51-6db1-569e-b858-859c34c0df5f
STIX ID: report--240b5e51-6db1-569e-b858-859c34c0df5f
Feed Name: securityonline.info
The report describes a renewed and expanded JDY botnet—linked to Chinese state-backed actors—now exceeding 1,500 compromised routers and IoT devices across multiple vendors and geographies. The botnet operates as a fast, distributed reconnaissance platform (using Tor, encrypted tasking, adaptive fingerprinting and SYN/TCP scans) that rapidly probes newly disclosed vulnerabilities (e.g., CVE-2026-35616) to harvest targeting data, with a primary focus on military-related networks; defenders are urged to patch edge devices, replace end-of-life routers, and consult the full Black Lotus Labs analysis for indicators and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
