INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

China-Linked Botnet Expands to 1,500+ Devices for Reconnaissance

| 2026-06-10 16:08 CRITICAL HIGH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The China-linked JDY botnet has expanded to 1,500+ compromised devices globally, with a significant surge in its size following the takedown of KV-botnet by US authorities. The malware's expansion is attributed to an industrialized reconnaissance effort leveraged by Chinese nation-state groups. Most of the hacked nodes are located in the U.S., Brazil, Europe, and Asia, with blacklisted IoT devices making up over 1,500 compromised units. The botnet comprises a diverse range of devices from various manufacturers, including Cisco RV320 and RV325 routers, Araknis AN-300-RT-4L2W, Mimosa Networks' Draytek Vigor3900 Series, Ubiquiti's Hikvision IP cameras, and Linksys LRT224. The malware has expanded its scope to infect a broader range of devices and act as a conduit for structured reconnaissance data feeding into a larger scanning ecosystem for follow-on target identification and exploitation.
Technical Mitigations AI-generated
• Implement a layered architecture that includes Tor nodes to manage infected infrastructure, including command-and-control (C2) and payload servers. • Use secure communication protocols such as HTTPS or SFTP for data transfer between the botnet operators and compromised devices. • Regularly update and patch vulnerable devices to prevent exploitation of known security flaws. • Implement a robust intrusion detection system (IDS) that can detect and block suspicious activity on infected devices.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Volt TyphoonVolt Typhoon CVE-2026-35616CVE-2026-35616 CVE-2023-20118CVE-2023-20118 CVE-2022-32548CVE-2022-32548 CVE-2023-24738CVE-2023-24738 CVE-2021-36260CVE-2021-36260
Target & Sectors
NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE defensedefense
Incident Timeline
‎late 2023
The JDY Botnet expanded to target military networks in late 2023.
tactic Botnet
‎mid-December 2023
The JDY botnet was first flagged as a cluster within the KV-botnet, which targeted military networks in mid-December 2023.
tactic Botnet
‎the start of January 2024
The botnet expanded to target military networks.
tactic Botnet
infrastructure 1,500 + Devices
general_metric 650 bots
‎January 2024
Threat actors used JDY's compromised SOHO and IoT devices to target military networks.
general_metric 650 bots
organisation JDY’s
organisation SOHO
organisation IoT
general_metric 1,500 SOHO
‎early 2024
Threat actors used the KV-botnet to target military networks.
tactic Botnet
industry Government
‎April 5, 2026
General Document Context Black Lotus Labs discovered a sharp spike in scans of Fortinet devices hours after CVE-2026-35616 was publicly disclosed on April 5, 2026.
organisation Black Lotus Labs
vulnerability CVE-2026-35616
organisation Fortinet
‎2026/06/10
The threat actors used JDY's botnet to target the security firm.
organisation SOHO
organisation IoT
general_metric 1,500 SOHO
general_metric 650 bots
‎2026/06/10
JDY Botnet Evolves After KV Takedown Targets Military Networks.
infrastructure 1,500 + Devices
threat_actor Volt Typhoon
organisation APT
organisation JDY
organisation SOHO
organisation IoT
organisation The Hacker News
organisation Cisco RV320
organisation RV325
organisation Mimosa Networks
organisation Draytek, Hikvision
organisation Linksys
organisation Cisco RV042 - Possibly
organisation SOHO/IoT
organisation IP
infrastructure 24738 Hikvision IP cameras
organisation Tor
organisation SecurityAffairs
organisation TLS
organisation TCP
organisation SSL
organisation Black Lotus Labs
organisation UDP
organisation Lumen’s Black Lotus Labs
organisation mips
organisation DrayTek
organisation MIPSEL
organisation Fortinet
organisation the FortiClient EMS
organisation IoT/SOHO
organisation Lumen Black Lotus Labs
organisation SYN
organisation EDR
‎2026/06/11
Threat actors used Araknis routers to target military networks.
tactic Botnet
organisation Cisco RV320
organisation RV325
organisation Mimosa Networks
organisation Draytek, Hikvision
organisation Linksys
Tactical Metrics
Metrics
infrastructure
1,500
+ Devices
Metrics
infrastructure
24,738
Hikvision Ip Cameras
Intelligence Sources