China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
ID: 1fc72882-5a3b-5333-9f68-bbc26d10b309
STIX ID: report--1fc72882-5a3b-5333-9f68-bbc26d10b309
Feed Name: The Hacker News
**JDY botnet resurgence:** JDY is a covert, high-performance SOHO/IoT reconnaissance botnet tied to China-nexus state-sponsored actors that has grown from ~650 to over 1,500 compromised devices and performs targeted scanning, fingerprinting, and data collection (including TLS metadata) to support downstream exploitation; it leverages Tor for C2, exploits disclosed edge-device vulnerabilities (e.g., CVE-2026-35616) to propagate, and its distributed footprint across U.S., Brazil, Europe, and Asia helps it evade IP-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
