Lumen’s Black Lotus Labs reports that the JDY botnet has expanded to over 1,500 compromised IoT and SOHO devices, serving as a sophisticated reconnaissance tool for state-sponsored hacking groups.
Key Points
- The JDY botnet has more than doubled in size since January 2024, now targeting hardware from manufacturers including Ubiquiti, Hikvision, Linksys, and Cisco.
- Operators utilize hidden Tor services and fileless malware execution to maintain command-and-control while evading detection by security software.
- The network performs high-performance scanning to map exposed services, often identifying vulnerable targets within hours of public vulnerability disclosures.
- Most infected nodes are located in the United States, allowing attackers to bypass geofencing and blend malicious traffic with legitimate user activity.
- Data collected by the botnet is used to support follow-on exploitation, with significant targeting observed against U.S. military networks and associated infrastructure.