Particle.news
Download on the App Store

China-Linked JDY Botnet Grows Into Recon Network Targeting U.S. Military

Researchers say the botnet feeds timely, structured targeting data to China-nexus APTs by scanning exposed routers and IoT devices through Tor-hidden control servers.

Overview

  • The Black Lotus Labs report, published June 10, 2026, says JDY now controls more than 1,500 compromised SOHO routers and IoT devices after growing from about 650 in January 2024.
  • JDY is built for reconnaissance: it harvests service banners, TLS certificates, protocol fingerprints, and other metadata to map exposed infrastructure for follow-on attacks.
  • Operators run command-and-control through Tor hidden services and sometimes use the open-source Platypus tool to dispatch scanning tasks and collect results from infected hosts.
  • The network adapts its scanning method to local privileges, using raw SYN scans when it has root access and falling back to TCP, TLS, UDP or ICMP probes when it does not.
  • Black Lotus Labs and CISA urge patching, removing internet-exposed router management interfaces, replacing default credentials, and monitoring outbound scanning because JDY quickly targets newly disclosed flaws such as CVE-2026-35616.