Thenextweb
JDY Botnet Grows to 1,500 Devices for Rapid Vulnerability Mapping
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The JDY botnet, linked to Chinese state-sponsored actors, has expanded to over 1,500 compromised small office and IoT devices, primarily in the U.S. and Brazil. This botnet scans for newly disclosed vulnerabilities within hours, feeding targeting data to state hackers. Initially part of the KV-botnet, JDY has evolved into an independent reconnaissance tool following the takedown of KV in early 2024. The botnet employs a diverse range of devices, including routers and firewalls from various manufacturers, to evade detection. Its architecture utilizes Tor nodes for command and control, enabling high-speed scanning and data collection. JDY's activities highlight a significant shift in reconnaissance tactics, focusing on infrastructure mapping rather than direct attacks. This poses a growing challenge for enterprise security teams, as many edge systems remain poorly monitored.
Key Points: • JDY botnet has expanded to over 1,500 compromised devices for reconnaissance. • The botnet scans for vulnerabilities within hours of public disclosure, aiding state hackers. • JDY's architecture allows it to evade detection by blending in with legitimate traffic.