Overview
- The Black Lotus Labs report, published June 10, 2026, says JDY now controls more than 1,500 compromised SOHO routers and IoT devices after growing from about 650 in January 2024.
- JDY is built for reconnaissance: it harvests service banners, TLS certificates, protocol fingerprints, and other metadata to map exposed infrastructure for follow-on attacks.
- Operators run command-and-control through Tor hidden services and sometimes use the open-source Platypus tool to dispatch scanning tasks and collect results from infected hosts.
- The network adapts its scanning method to local privileges, using raw SYN scans when it has root access and falling back to TCP, TLS, UDP or ICMP probes when it does not.
- Black Lotus Labs and CISA urge patching, removing internet-exposed router management interfaces, replacing default credentials, and monitoring outbound scanning because JDY quickly targets newly disclosed flaws such as CVE-2026-35616.