China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance

China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance β€” Cybersecurity | Versia.media

Cybersecurity researchers have issued warnings about a "resurgence and expansion" of JDY, a covert network linked to China-linked state-sponsored threat actors.

"The JDY botnet consists of over 1,500 SOHO [small office and home office] and IoT devices and functions as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale," Lumen's Black Lotus Labs stated in a report provided to The Hacker News.

JDY was initially identified as a subgroup within another botnet known as KV-botnet in mid-December 2023. Primarily employed for large-scale scanning of internet targets, this stealthy network, composed of compromised SOHO routers, firewalls, and IoT devices, has been utilized by Chinese hacking groups such as Volt Typhoon.

After the U.S. government dismantled KV-botnet in early 2024, the botnet operators started implementing behavioral modifications to the network, with the second KV cluster largely going offline. It is believed that the operators offer the botnet to various hacking groups, while also conducting reconnaissance and targeting on their own behalf.

The latest findings from Black Lotus Labs indicate that the malware has broadened its scope to infect a wider array of devices and serve as a channel to supply "structured reconnaissance data" into a larger scanning ecosystem for subsequent target identification and exploitation.

Specifically, the JDY cluster is being utilized to perform targeted scanning and service fingerprinting with the objective of identifying vulnerable infrastructure following public disclosures. This suggests an industrialized reconnaissance effort, with the results being leveraged by Chinese state-sponsored groups.

This development has been accompanied by an increase in the botnet's size, which has grown from 650 bots at the beginning of January 2024 to over 1,500 compromised devices. Most of the hacked nodes are situated in the U.S. and Brazil, followed by Europe and Asia. Black Lotus Labs informed The Hacker News that the cluster in Brazil reflects the fact that "we're seeing more and more botnets made up of Brazilian victims these days."

Whereas the cluster previously mainly featured Cisco RV320 and RV325 routers, the current composition of the botnet is significantly more varied, encompassing devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.

The vast majority of the victim devices are assessed to have reached end-of-life (EoL) with known vulnerabilities. While the precise nature of the security flaws remains uncertain, it is suspected to involve the following based on the specific device models being exploited:

Cisco RV042 - Possibly vulnerable to flaws like CVE-2023-20118

Cisco RV042 - Possibly vulnerable to flaws like CVE-2023-20118

DrayTek Vigor3900 Series - Possibly vulnerable to flaws like CVE-2022-32548

DrayTek Vigor3900 Series - Possibly vulnerable to flaws like CVE-2022-32548

Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like CVE-2023-24738

Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like CVE-2023-24738

Hikvision IP cameras - Possibly vulnerable to flaws like CVE-2021-36260

Hikvision IP cameras - Possibly vulnerable to flaws like CVE-2021-36260

Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web

Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web

"The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs stated.

"By distributing their scanning and reconnaissance activity across a wide range of IP addresses, the operators make it less likely that any single IP will be labeled as a scanner and blocked. Additionally, using compromised SOHO and IoT devices helps this activity blend in with legitimate user traffic."

The architecture that powers the botnet is best characterized as layered: the operators use Tor nodes to manage infected infrastructure, including both the command-and-control (C2) and payload servers. The C2 servers direct the bots to perform targeted reconnaissance and system profiling, rather than indiscriminate scanning. Results of the scans are sent to central servers for ongoing intelligence gathering in an effort to further Chinese threat actors' objectives.

Attack chains weaponize newly disclosed vulnerabilities in edge devices (e.g., CVE-2026-35616) to deliver a shell script dropper that checks if the malware is already active, and if not, proceeds to download the primary payload based on the detected processor architecture (e.g., mips, mips64, mipsel, or mipsel64). Once the malware is launched, it's deleted from disk.

The malware that facilitates scanning and target reconnaissance is designed to fingerprint the host, receive scanning tasks from a central C2 server, carry out high-volume TCP, SSL, UDP, and ICMP-assisted probing, capture responses (TLS certificates, metadata, etc.), and report the results back to the dispatch server. The goal is to conduct infrastructure reconnaissance rather than exploitation.

A noteworthy functionality of the malware is its ability to adapt its scanning methodology based on its privileges on the local system. If it can open a raw socket, an indication of root privileges, it initiates high-speed SYN scanning using custom-crafted TCP packets. If raw sockets are unavailable or if the task is a web scan, the scanning engine resorts to using standard TCP and TLS connections or employs protocols like UDP and ICMP.

This activity most likely informs asset discovery, vulnerability-targeting pipelines, and downstream exploitation or attack-orchestration systems, the cybersecurity company said.

"JDY demonstrates how IoT/SOHO botnets and covert networks of compromised devices are being used for rapid vulnerability exploitation," the company said. "JDY's growth and continued operation illustrate how modern reconnaissance networks persist despite takedowns and adapt as a durable capability within a broader adversary ecosystem."

"JDY's evolution from a supporting component of the KV-botnet to an independent, high-performance reconnaissance capability demonstrates that disruption of individual nodes or clusters does not eliminate the underlying capability. The capability persists, adapts, and continues to provide adversaries with timely targeting data, often within hours of vulnerability disclosure."

(The story was updated after publication to include additional insights from Lumen Black Lotus Labs.)

← Cybersecurity