China-linked JDY botnet expands targeting of U.S. military networks
ID: a30aad8b-af0c-5234-8518-e6d81c40a633
STIX ID: report--a30aad8b-af0c-5234-8518-e6d81c40a633
Feed Name: Bleeping Computer
The JDY botnet, attributed to China-nexus APT operators (previously associated with Volt Typhoon), has expanded to roughly 1,500 compromised SOHO and IoT devices and is being used as a distributed reconnaissance network focused on U.S. military and associated targets; it performs TCP/UDP/ICMP scanning, TLS certificate harvesting, banner collection, and protocol fingerprinting, uses Tor hidden services for C2, and rapidly operationalizes scans against newly disclosed vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
