- What: JDY botnet expands and exploits vulnerabilities
- Impact: Targets SOHO and IoT devices
Threat Intelligence JDY botnet expands, enabling rapid exploitation of disclosed vulnerabilities June 10, 2026 Share By SC Staff Cybersecurity researchers at Lumen's Black Lotus Labs have identified a significant resurgence and expansion of the JDY botnet, a covert network linked to Chinese state-sponsored threat actors. This botnet, comprising over 1,500 compromised small office/home office (SOHO) and IoT devices, functions as a high-performance scanner for discovering and mapping exposed services at scale, according to a recent report by The Hacker News. Initially flagged as part of the KV-botnet, JDY has evolved into an independent reconnaissance capability following the U.S. government's takedown of KV in early 2024. The JDY cluster now infects a wider range of devices, including those from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys, with a surge in compromised devices from 650 to over 1,500. Primarily located in the U.S. and Brazil, these devices are used to conduct targeted scanning and service fingerprinting, identifying vulnerable infrastructure shortly after public disclosures. This industrialized reconnaissance effort feeds data into a larger scanning ecosystem for follow-on target identification and exploitation. The botnet's architecture uses Tor nodes for management and command-and-control servers that direct bots to perform detailed system profiling. Attack chains weaponize newly disclosed vulnerabilities in edge devices to deliver a shell script dropper, which then downloads the primary payload. The malware adapts its scanning methodology based on system privileges, utilizing high-speed SYN scanning when possible or resorting to standard TCP and TLS connections. This activity informs asset discovery, vulnerability-targeting pipelines, and downstream exploitation systems, demonstrating how IoT/SOHO botnets persist and adapt as a durable capability within adversary ecosystems. Source: The Hacker News SC Staff Related Threat Intelligence Tempo news website hit by massive DDoS cyberattack SC Staff June 9, 2026 Tempo's technology team reported that the cyberattack generated an unprecedented volume of bot-generated traffic, placing immense pressure on their infrastructure. Threat Intelligence Iranian-linked hackers claim cyberattack on Israeli military, but evidence is weak SC Staff June 9, 2026 As reported by HackRead, an Iranian-linked hacker group named Handala claimed on Sunday, June 7, 2026, to have conducted significant cyberattacks against Israeli military targets, including disrupting signal networks and radar systems. Threat Intelligence American citizen pleads guilty to spying for China SC Staff June 8, 2026 Thomas Weir Pauken II, 50, admitted to conspiring with multiple individuals to exfiltrate data for the Chinese government. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Botnet Brute Force Deepfake Denial of Service Dictionary Attack Distributed Scans Drive-by Download Google Hacking Hybrid Attack You can skip this ad in 5 seconds