logo

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

ID: 1fc72882-5a3b-5333-9f68-bbc26d10b309

STIX ID: report--1fc72882-5a3b-5333-9f68-bbc26d10b309

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-10

Date Updated: 2026-06-11

Author: [email protected] (The Hacker News)

...
...

**JDY botnet resurgence:** JDY is a covert, high-performance SOHO/IoT reconnaissance botnet tied to China-nexus state-sponsored actors that has grown from ~650 to over 1,500 compromised devices and performs targeted scanning, fingerprinting, and data collection (including TLS metadata) to support downstream exploitation; it leverages Tor for C2, exploits disclosed edge-device vulnerabilities (e.g., CVE-2026-35616) to propagate, and its distributed footprint across U.S., Brazil, Europe, and Asia helps it evade IP-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.