China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
Researchers say JDY has grown into a 1,500-device botnet used for targeted reconnaissance and service fingerprinting across exposed systems.
Intelligence analysis by GPT-5.4 Mini

Lumen’s Black Lotus Labs says JDY has resurfaced as a larger, more diverse botnet that feeds structured reconnaissance data into a broader scanning ecosystem. The network is tied to China-nexus threat activity and is being used to map exposed services and support follow-on targeting.
JDY is like a secret crew of stolen home and office gadgets that takes turns looking for weak doors on the internet. Because the devices are spread out around the world, the searching looks more like normal traffic and is harder to block.
Analysis
What JDY is doing
Black Lotus Labs says JDY is a covert botnet associated with China-nexus state-sponsored actors and now includes more than 1,500 compromised SOHO and IoT devices. The group describes it as a centrally controlled, high-performance scanner built to discover, fingerprint, and continuously map exposed services at scale.
How it changed
The botnet was first identified as part of the KV-botnet cluster in December 2023. After the U.S. government disrupted KV-botnet in early 2024, the operators changed behavior, and the second KV cluster mostly went offline. Since then, JDY appears to have expanded and diversified, moving beyond the earlier concentration of Cisco RV320 and RV325 routers to include devices from Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision, and Linksys.
What the researchers saw
The report says most infected nodes are in the U.S. and Brazil, with others in Europe and Asia. Lumen says the botnet uses Tor nodes to manage both command-and-control and payload servers, and that the C2 directs bots toward targeted reconnaissance rather than indiscriminate scanning. The malware can run high-volume TCP, SSL, UDP, and ICMP probing, capture responses such as TLS certificates and metadata, and send the results back for analysis.
Why that matters
The key point is not just scale, but purpose: the activity appears aimed at infrastructure reconnaissance, not immediate exploitation. Black Lotus Labs says the results likely feed asset discovery, vulnerability targeting, and downstream attack-orchestration systems. The company also says JDY’s U.S.-based devices help operators evade geofencing, IP reputation filters, and static blocklists by spreading activity across many apparently ordinary residential and small-office IPs.
The report frames JDY as a resilient capability that persists even after takedowns, adapting quickly to new disclosures and continuing to provide targeting data within hours.
Key points
- JDY has grown from about 650 bots in early January 2024 to more than 1,500 compromised devices.
- Black Lotus Labs says the botnet is tied to China-nexus state-sponsored activity and used for reconnaissance.
- Most infected nodes are in the U.S. and Brazil, with additional devices in Europe and Asia.
- The botnet now includes a wider mix of SOHO and IoT hardware, not just Cisco routers.
- Researchers say JDY helps attackers fingerprint exposed services and feed follow-on targeting systems.
If defenders use these findings well, they can hunt for the botnet’s scanning patterns, improve blocklists, and close exposed services faster after new flaws are disclosed. The report also gives security teams more detail about the kinds of devices and traffic patterns involved.
If the botnet keeps growing, attackers can keep using it as a durable source of reconnaissance data and a launch point for later attacks. Its spread across many ordinary IPs may continue to weaken geofencing, reputation filters, and other IP-based defenses.



