AUTO-UPDATED

JDY Botnet Evolves After KV Takedown, Targets Military Networks

Lumen’s Black Lotus Labs reports that the JDY botnet has expanded to over 1,500 compromised IoT and SOHO devices, serving as a sophisticated reconnaissance tool for state-sponsored hacking groups.

Key Points

  • The JDY botnet has more than doubled in size since January 2024, now targeting hardware from manufacturers including Ubiquiti, Hikvision, Linksys, and Cisco.
  • Operators utilize hidden Tor services and fileless malware execution to maintain command-and-control while evading detection by security software.
  • The network performs high-performance scanning to map exposed services, often identifying vulnerable targets within hours of public vulnerability disclosures.
  • Most infected nodes are located in the United States, allowing attackers to bypass geofencing and blend malicious traffic with legitimate user activity.
  • Data collected by the botnet is used to support follow-on exploitation, with significant targeting observed against U.S. military networks and associated infrastructure.

Why it Matters

The resurgence of JDY demonstrates that disrupting individual botnet clusters is insufficient to eliminate persistent, state-sponsored reconnaissance capabilities. This evolving threat highlights the critical risk posed by unpatched IoT devices, which attackers increasingly leverage to map and prepare for large-scale cyber operations against sensitive infrastructure.
Securityaffairs.com Published by Pierluigi Paganini
Read original