INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
China-Linked Botnet Expands to 1,500+ Devices for Reconnaissance
| 2026-06-10 16:08 CRITICAL HIGH MALWARE & BOTNETS STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The China-linked JDY botnet has expanded to 1,500+ compromised devices globally, with a significant surge in its size following the takedown of KV-botnet by US authorities. The malware's expansion is attributed to an industrialized reconnaissance effort leveraged by Chinese nation-state groups. Most of the hacked nodes are located in the U.S., Brazil, Europe, and Asia, with blacklisted IoT devices making up over 1,500 compromised units. The botnet comprises a diverse range of devices from various manufacturers, including Cisco RV320 and RV325 routers, Araknis AN-300-RT-4L2W, Mimosa Networks' Draytek Vigor3900 Series, Ubiquiti's Hikvision IP cameras, and Linksys LRT224. The malware has expanded its scope to infect a broader range of devices and act as a conduit for structured reconnaissance data feeding into a larger scanning ecosystem for follow-on target identification and exploitation.
Technical Mitigations AI-generated
• Implement a layered architecture that includes Tor nodes to manage infected infrastructure, including command-and-control (C2) and payload servers.
• Use secure communication protocols such as HTTPS or SFTP for data transfer between the botnet operators and compromised devices.
• Regularly update and patch vulnerable devices to prevent exploitation of known security flaws.
• Implement a robust intrusion detection system (IDS) that can detect and block suspicious activity on infected devices.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Volt TyphoonVolt Typhoon
CVE-2026-35616CVE-2026-35616
CVE-2023-20118CVE-2023-20118
CVE-2022-32548CVE-2022-32548
CVE-2023-24738CVE-2023-24738
CVE-2021-36260CVE-2021-36260
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
EUROPE
EUROPE
defensedefense
Incident Timeline
late 2023
The JDY Botnet expanded to target military networks in late 2023.
Click on any entity below to view its context and source!
tactic
Botnet
The network was first spotted in late 2023 as a cluster inside KV-botnet.
mid-December 2023
The JDY botnet was first flagged as a cluster within the KV-botnet, which targeted military networks in mid-December 2023.
Click on any entity below to view its context and source!
tactic
Botnet
JDY was
first flagged
as a cluster within another botnet codenamed KV-botnet in mid-December 2023.
the start of January 2024
The botnet expanded to target military networks.
Click on any entity below to view its context and source!
tactic
Botnet
This has been complemented by a growth in the botnet's size, which has surged from 650 bots at the start of January 2024 to more than 1,500 compromised devices.
infrastructure
1,500 + Devices
This has been complemented by a growth in the botnet's size, which has surged from 650 bots at the start of January 2024 to more than 1,500 compromised devices.
general_metric
650 bots
This has been complemented by a growth in the botnet's size, which has surged from 650 bots at the start of January 2024 to more than 1,500 compromised devices.
January 2024
Threat actors used JDY's compromised SOHO and IoT devices to target military networks.
Click on any entity below to view its context and source!
general_metric
650 bots
That’s more than double the roughly 650 bots recorded at JDY’s lowest point in January 2024.
The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.
organisation
JDY’s
That’s more than double the roughly 650 bots recorded at JDY’s lowest point in January 2024.
organisation
SOHO
The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.
organisation
IoT
The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.
general_metric
1,500 SOHO
The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.
early 2024
Threat actors used the KV-botnet to target military networks.
Click on any entity below to view its context and source!
tactic
Botnet
Following KV-botnet's
takedown
by the U.S. government in early 2024, the botnet operators began making
behavioral changes
to the network, with the second KV cluster largely going offline.
industry
Government
Following KV-botnet's
takedown
by the U.S. government in early 2024, the botnet operators began making
behavioral changes
to the network, with the second KV cluster largely going offline.
The U.S. government took down the KV cluster in early 2024.
April 5, 2026
General Document Context Black Lotus Labs discovered a sharp spike in scans of Fortinet devices hours after CVE-2026-35616 was publicly disclosed on April 5, 2026.
Click on any entity below to view its context and source!
organisation
Black Lotus Labs
Black Lotus Labs found a sharp spike in scans of Fortinet devices hours after
CVE-2026-35616
was publicly disclosed on April 5, 2026.
vulnerability
CVE-2026-35616
Black Lotus Labs found a sharp spike in scans of Fortinet devices hours after
CVE-2026-35616
was publicly disclosed on April 5, 2026.
organisation
Fortinet
Black Lotus Labs found a sharp spike in scans of Fortinet devices hours after
CVE-2026-35616
was publicly disclosed on April 5, 2026.
2026/06/10
The threat actors used JDY's botnet to target the security firm.
Click on any entity below to view its context and source!
organisation
SOHO
The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.
organisation
IoT
The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.
general_metric
1,500 SOHO
The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.
general_metric
650 bots
The security firm notes that JDY has grown from roughly 650 active bots in January 2024 to over 1,500 compromised SOHO and IoT devices today.
2026/06/10
JDY Botnet Evolves After KV Takedown Targets Military Networks.
Click on any entity below to view its context and source!
infrastructure
1,500 + Devices
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance.
threat_actor
Volt Typhoon
Primarily used for broader scanning against internet targets, the stealthy network comprising compromised SOHO routers, firewalls, and IoT devices has been put to use by Chinese hacking groups like Volt Typhoon.
Lumen’s Black Lotus Labs reported the resurgence of the JDY botnet, a covert reconnaissance network tied to Chinese state-sponsored hacking groups including
Volt Typhoon
.
The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts.
"
Most impacted countries by the JDY botnet
Source: Black Lotus Labs
CISA has
previously warned
about the risk Volt Typhoon operatives pose to unprotected SOHO routers, urging network device vendors to eliminate vulnerabilities in SOHO router web management interfaces (WMIs) during the design and development phases.
organisation
APT
"Analysis of this activity shows a clear focus on identifying vulnerable infrastructure shortly after public vulnerability disclosures, suggesting that reconnaissance output is rapidly operationalized by China-nexus advanced persistent threat (APT) actors," reads the
Black Lotus Labs report
.
organisation
JDY
The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts.
Specifically, the JDY cluster is being used to conduct targeted scanning and service fingerprinting with an aim to flag vulnerable infrastructure following public disclosures.
What JDY does with its results makes the intent clear.
organisation
SOHO
"The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale," Lumen's Black Lotus Labs
said
in a report shared with The Hacker News.
“The JDY botnet comprises over 1,500 small office and home office (SOHO) and Internet of Things (IoT) devices.
organisation
IoT
"The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale," Lumen's Black Lotus Labs
said
in a report shared with The Hacker News.
“The JDY botnet comprises over 1,500 small office and home office (SOHO) and Internet of Things (IoT) devices.
organisation
The Hacker News
"The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale," Lumen's Black Lotus Labs
said
in a report shared with The Hacker News.
organisation
Cisco RV320
"
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
organisation
RV325
"
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
organisation
Mimosa Networks
"
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
Among the compromised devices are those from Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, for MIPS, MIPS64, MIPSEL, and MIPSEL64 architectures.
organisation
Draytek, Hikvision
"
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
organisation
Linksys
"
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
Where previously the cluster primarily featured Cisco RV320 and RV325 routers, the present makeup of the botnet is a lot more diverse, including devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
Among the compromised devices are those from Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, for MIPS, MIPS64, MIPSEL, and MIPSEL64 architectures.
organisation
Cisco RV042 - Possibly
Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited -
Cisco RV042 - Possibly vulnerable to flaws like
CVE-2023-20118
DrayTek Vigor3900 Series - Possibly vulnerable to flaws like
CVE-2022-32548
Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like
CVE-2023-24738
Hikvision IP cameras - Possibly vulnerable to flaws like
CVE-2021-36260
Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web
"The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.
organisation
SOHO/IoT
Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited -
Cisco RV042 - Possibly vulnerable to flaws like
CVE-2023-20118
DrayTek Vigor3900 Series - Possibly vulnerable to flaws like
CVE-2022-32548
Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like
CVE-2023-24738
Hikvision IP cameras - Possibly vulnerable to flaws like
CVE-2021-36260
Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web
"The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.
JDY Botnet Evolves After KV Takedown, Targets Military Networks
JDY botnet scans SOHO/IoT devices globally to map services and targets, especially US military networks.
"The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.
organisation
IP
Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited -
Cisco RV042 - Possibly vulnerable to flaws like
CVE-2023-20118
DrayTek Vigor3900 Series - Possibly vulnerable to flaws like
CVE-2022-32548
Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like
CVE-2023-24738
Hikvision IP cameras - Possibly vulnerable to flaws like
CVE-2021-36260
Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web
"The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.
“The botnet’s large number of U.S.-based SOHO and IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection and static blocklists.
"The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.
infrastructure
24738 Hikvision IP cameras
Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited -
Cisco RV042 - Possibly vulnerable to flaws like
CVE-2023-20118
DrayTek Vigor3900 Series - Possibly vulnerable to flaws like
CVE-2022-32548
Araknis AN-300-RT-4L2W - Possibly vulnerable to flaws like
CVE-2023-24738
Hikvision IP cameras - Possibly vulnerable to flaws like
CVE-2021-36260
Linksys LRT224 - No known CVEs, but alleged zero-days have been sold on the dark web
"The botnet's large number of U.S.-based SOHO/IoT devices enables the botnet operators to evade defenses and traditional IP-based controls, such as geofencing, IP reputation-based detection, and static blocklists," Black Lotus Labs said.
organisation
Tor
The architecture that powers the botnet is best described as layered: the operators use Tor nodes to manage infected infrastructure, including both the command-and-control (C2) and payload servers.
JDY targeting volume on a specific date
Source: Black Lotus Labs
The operators control the botnet through hidden Tor services, which also serve as command-and-control (C2) infrastructure.
Operators connect to infected devices through hidden Tor services that hide both the command-and-control servers and the payload servers.
organisation
SecurityAffairs
“The capability persists, adapts and continues to provide adversaries with timely targeting data, often within hours of vulnerability disclosure.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, JDY botnet)
organisation
TLS
The JDY botnet is designed to conduct service discovery, service banner grabbing, TLS certificate collection, protocol fingerprinting, and flaw-focused reconnaissance.
Without raw socket access, it falls back to standard TCP and TLS connections and collects richer data: banners, SSL/TLS versions, certificate metadata, redirect paths, HTTP responses.
If raw sockets are unavailable or if the task is a web scan, the scanning engine resorts to using standard TCP and TLS connections or employs protocols like UDP and ICMP.
organisation
TCP
The scanning module supports the following:
TCP scanning
SSL/TLS scanning
UDP scanning
ICMP probing
Banner collection
TLS certificate harvesting
Service fingerprinting using downloadable rule sets
The botnet client repeats the same cycle until the operator specifically orders it to stop.
The malware that facilitates scanning and target reconnaissance is designed to fingerprint the host, receive scanning tasks from a central C2 server, carry out high-volume TCP, SSL, UDP, and ICMP-assisted probing, capture responses (TLS certificates, metadata, etc.), and report the results back to the dispatch server.
With root access and a raw socket, it fires SYN packets using custom-crafted TCP packets, scanning thousands of targets per batch without completing a handshake, which means no application-level logging on the target.
organisation
SSL
The scanning module supports the following:
TCP scanning
SSL/TLS scanning
UDP scanning
ICMP probing
Banner collection
TLS certificate harvesting
Service fingerprinting using downloadable rule sets
The botnet client repeats the same cycle until the operator specifically orders it to stop.
The malware that facilitates scanning and target reconnaissance is designed to fingerprint the host, receive scanning tasks from a central C2 server, carry out high-volume TCP, SSL, UDP, and ICMP-assisted probing, capture responses (TLS certificates, metadata, etc.), and report the results back to the dispatch server.
Without raw socket access, it falls back to standard TCP and TLS connections and collects richer data: banners, SSL/TLS versions, certificate metadata, redirect paths, HTTP responses.
organisation
Black Lotus Labs
The latest findings from Black Lotus Labs show that the malware has expanded in scope to infect a broader range of devices and act as a conduit to feed "structured reconnaissance data" into a larger scanning ecosystem for follow-on target identification and exploitation.
According to researchers at Black Lotus Labs by Lumen, who have been monitoring its activity, JDY maintains a strong focus on the United States, where many of its compromised devices are located and where it heavily targets military and associated networks.
organisation
UDP
The malware that facilitates scanning and target reconnaissance is designed to fingerprint the host, receive scanning tasks from a central C2 server, carry out high-volume TCP, SSL, UDP, and ICMP-assisted probing, capture responses (TLS certificates, metadata, etc.), and report the results back to the dispatch server.
organisation
Lumen’s Black Lotus Labs
“The JDY malware focuses on infrastructure reconnaissance rather than exploiting targets, which likely supports follow-on asset discovery, vulnerability-targeting pipelines and downstream exploitation or attack-orchestration systems.” states Lumen’s Black Lotus Labs.
organisation
mips
Among the compromised devices are those from Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, for MIPS, MIPS64, MIPSEL, and MIPSEL64 architectures.
Attack chains weaponize newly disclosed vulnerabilities in edge devices (e.g., CVE-2026-35616) to deliver a shell script dropper that checks if the malware is already active, and if not, proceeds to download the primary payload based on the detected processor architecture (e.g., mips, mips64, mipsel, or mipsel64).
organisation
DrayTek
Among the compromised devices are those from Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, for MIPS, MIPS64, MIPSEL, and MIPSEL64 architectures.
organisation
MIPSEL
Among the compromised devices are those from Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys, for MIPS, MIPS64, MIPSEL, and MIPSEL64 architectures.
organisation
Fortinet
The threat actors are quick to target newly disclosed vulnerabilities, with Lumen researchers observing JDY scans targeting CVE-2026-35616 shortly after Fortinet publicly disclosed the FortiClient EMS flaw.
organisation
the FortiClient EMS
The threat actors are quick to target newly disclosed vulnerabilities, with Lumen researchers observing JDY scans targeting CVE-2026-35616 shortly after Fortinet publicly disclosed the FortiClient EMS flaw.
organisation
IoT/SOHO
"JDY demonstrates how IoT/SOHO botnets and covert networks of compromised devices are being used for rapid vulnerability exploitation," the company said.
organisation
Lumen Black Lotus Labs
"
(The story was updated after publication to include additional insights from Lumen Black Lotus Labs.)
organisation
SYN
The TCP scanning function is one of the most technically interesting, say the researchers, explaining that, when JDY has sufficient privileges, it performs much faster and stealthier raw SYN scanning.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
2026/06/11
Threat actors used Araknis routers to target military networks.
Click on any entity below to view its context and source!
tactic
Botnet
The device list has diversified too: where the old botnet ran almost exclusively on Cisco RV320 and RV325 routers, today’s JDY pulls in hardware from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
organisation
Cisco RV320
The device list has diversified too: where the old botnet ran almost exclusively on Cisco RV320 and RV325 routers, today’s JDY pulls in hardware from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
organisation
RV325
The device list has diversified too: where the old botnet ran almost exclusively on Cisco RV320 and RV325 routers, today’s JDY pulls in hardware from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
organisation
Mimosa Networks
The device list has diversified too: where the old botnet ran almost exclusively on Cisco RV320 and RV325 routers, today’s JDY pulls in hardware from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
organisation
Draytek, Hikvision
The device list has diversified too: where the old botnet ran almost exclusively on Cisco RV320 and RV325 routers, today’s JDY pulls in hardware from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
organisation
Linksys
The device list has diversified too: where the old botnet ran almost exclusively on Cisco RV320 and RV325 routers, today’s JDY pulls in hardware from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
Tactical Metrics
Metrics
infrastructure
1,500
+ Devices
Click for context!
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance.
This has been complemented by a growth in the botnet's size, which has surged from 650 bots at the start of January 2024 to more than 1,500 compromised devices.
Metrics
infrastructure
24,738
Hikvision Ip Cameras
Although the exact nature of the security flaws remains unclear, it's suspected to involve the following based on the specific device models that are being exploited -
Cisco RV042 - Possibly vulnerable to flaws like
CVE-2023-20118
DrayT…
Intelligence Sources
Security Affairs
2026-06-11
JDY Botnet Evolves After KV Takedown, Targets Military Networks
Security Affairs
The Hacker News
2026-06-10
BleepingComputer
2026-06-10
China-linked JDY botnet expands targeting of U.S. military networks
BleepingComputer
The Hacker News
2026-06-10
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
31x
organisation
Identified Entity
SOHO
entity
9x
timeline
Temporal Reference
early 2024
date
5x
vulnerability
Exploited CVE
CVE-2023-20118
cve
3x
tactic
Cyber Operation Type
Botnet
tactic
3x
target region
Target Country
Brazil
country
2x
attribution
Attributing Entity
Lumen’s Black Lotus Labs
authority
2x
general metric
%
54
%
Contextual Telemetry
Context Block
11 METRICS
source region
Origin Country
China
country
tactic
MITRE ATT&CK Technique
T1584.005 - Botnet
technique
infrastructure
+ Devices
1,500
+ devices
target region
Target Region
EUROPE
region
industry
Targeted Sector
Government
sector
general metric
Soho
1,500
soho
general metric
Bots
650
bots
general metric
Draytek
20,118
draytek
general metric
Araknis An-300
32,548
araknis an-300
infrastructure
Hikvision Ip Cameras
24,738
hikvision ip cameras
threat actor
APT Group
Volt Typhoon
actor
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.