# China-Linked JDY Botnet Expanding Military Reconnaissance Network Across U.S. Infrastructure
The JDY botnet, attributed to Chinese state-sponsored threat actors, has more than doubled in size and intensity over the past 18 months, establishing itself as a sophisticated distributed reconnaissance platform with alarming focus on U.S. military networks and critical infrastructure. Security researchers at Black Lotus Labs by Lumen have documented the botnet's evolution from approximately 650 active nodes in January 2024 to over 1,500 compromised devices today, demonstrating a persistent and growing threat to national security.
The botnet's true danger lies not in its relatively modest size but in its operational sophistication and speed of execution. JDY functions as a specialized intelligence-gathering apparatus, rapidly identifying vulnerable systems following public vulnerability disclosures and feeding that reconnaissance data directly to advanced persistent threat (APT) operators—likely including notorious actors like Volt Typhoon—who move swiftly to exploit newly disclosed flaws.
## Background and Context
JDY's operational lineage traces directly to previous campaigns attributed to Chinese state-sponsored threat actors, particularly Volt Typhoon, which has been the subject of extensive public warnings from U.S. Cybersecurity and Infrastructure Security Agency (CISA) regarding attacks on critical infrastructure. The botnet represents a significant evolution in how Chinese threat actors conduct reconnaissance, shifting from sporadic vulnerability scanning to a systematized, distributed approach that scales across multiple device types and architectures.
CISA has previously issued detailed guidance about Volt Typhoon's exploitation of SOHO (Small Office/Home Office) and edge devices, specifically highlighting the danger of vulnerable web management interfaces on routers and network equipment. The JDY botnet appears to be the operational manifestation of these concerns, providing the infrastructure necessary to identify which of these vulnerable devices are exposed to the internet and accessible to attackers.
The timing of JDY's expansion is significant. Recent years have seen an explosion in the number of vulnerable IoT and SOHO devices on networks worldwide, particularly as remote work and distributed infrastructure became standard. This expansion of the attack surface has created ideal conditions for reconnaissance botnets, which can efficiently map vulnerable targets across entire geographic regions.
## The Threat: Operational Model and Objectives
Unlike traditional botnets designed for distributed denial-of-service (DDoS) attacks or mass-scale exploitation, JDY operates as a distributed scanning and fingerprinting network. Its primary function is reconnaissance—identifying vulnerable systems, collecting infrastructure signatures, and rapidly reporting findings back to command-and-control infrastructure where Chinese APT operators can operationalize the data for targeted attacks.
Black Lotus Labs researchers documented this operational pipeline:
1. New vulnerability disclosed publicly
2. JDY botnet receives scanning assignments targeting the flaw
3. Compromised devices execute reconnaissance across target networks
4. Reconnaissance data is collected and returned to operators
5. APT operators rapidly exploit identified vulnerable systems
This approach is decidedly asymmetric. It doesn't require massive computational resources or high-bandwidth command-and-control channels. Instead, it distributes the scanning workload across thousands of quietly compromised devices, making detection and mitigation significantly more challenging than centralized scanning infrastructure.
## Technical Architecture and Capabilities
### Infected Device Landscape
JDY compromises SOHO routers, network edge devices, and IoT systems from major manufacturers including:
| Manufacturer | Device Type |
|--------------|-------------|
| Cisco | Enterprise/SOHO routers |
| Ubiquiti | Wireless and edge equipment |
| Fortinet | Network appliances |
| DrayTek | Business routers |
| Hikvision | Surveillance systems |
| Linksys | Consumer/SOHO routers |
| Araknis | Managed switches |
| Mimosa Networks | Wireless infrastructure |
The botnet specifically targets devices running MIPS, MIPS64, MIPSEL, and MIPSEL64 processor architectures—ubiquitous in networking equipment but often overlooked in security patching cycles.
### Reconnaissance Capabilities
JDY's scanning module provides enterprise-grade reconnaissance functionality:
The most technically sophisticated component is JDY's TCP scanning function. When the malware achieves elevated privileges on compromised devices, it deploys raw socket SYN scanning, executing high-speed reconnaissance using custom-crafted TCP packets. The implementation uses a fixed source port of 19000 and processes batches of thousands of targets, balancing speed with stealth.
### Command and Control Infrastructure
JDY operators maintain command-and-control infrastructure through hidden Tor services, providing operational anonymity resistant to traditional network-level blocking. The architecture employs a "Dispatch Service" model where botnet clients register centrally, receive scanning assignments, execute reconnaissance, compress results, and report findings back through encrypted channels.
In some cases, operators supplement Tor-based C2 with Platypus, an open-source reverse-shell and host-management framework, providing flexibility in command execution and device management.
## Targeting and Impact Scope
### Geographic Focus
While JDY maintains operational activity globally, the United States is heavily overrepresented in Black Lotus Labs' tracking data. The concentration of compromised devices correlates closely with the distribution of targeted systems, indicating deliberate focus on U.S. military and defense-related networks.
### Rapid Vulnerability Operationalization
Researchers documented JDY actively scanning for CVE-2026-35616, a critical Fortinet FortiClient EMS vulnerability, shortly after Fortinet's public disclosure. This rapid pivot to newly disclosed flaws demonstrates the tight integration between reconnaissance operations and APT exploitation teams. The operational latency between disclosure and active targeting is measured in hours, not days—a clear indication that Chinese cyber operations have streamlined their vulnerability-to-exploitation pipeline.
### Sectoral Distribution
While military and defense contractors represent the primary focus, Black Lotus Labs identified scanning activity targeting:
## Implications for Organizations and Defenders
The expansion of JDY represents a qualitative shift in how sophisticated state-sponsored threat actors approach reconnaissance. Rather than conducting targeted scanning that risks detection, they've distributed the burden across thousands of compromised edge devices, creating a distributed intelligence network that's extremely difficult to shut down through traditional means.
Organizations should interpret JDY activity as an immediate precursor to targeted exploitation attempts. If your infrastructure is large enough to be scanned by a distributed reconnaissance botnet, you should assume that your publicly disclosed vulnerabilities are being actively mapped and that exploitation attempts are likely in development.
### Immediate Priorities
## HackWire Analysis
The JDY botnet's rapid operationalization of newly disclosed vulnerabilities—moving from public disclosure to active scanning in hours—reveals a critical gap in how defenders approach vulnerability management. The traditional 30-90 day patch window is increasingly untenable against adversaries who maintain distributed reconnaissance infrastructure optimized specifically for this kill chain.
What's particularly significant is the targeting profile. This isn't opportunistic cybercrime leveraging mass-market exploits. This is focused military reconnaissance with clear national security implications. The concentration of activity against U.S. military networks, paired with the rapid pivot to weaponize new disclosures, indicates that Chinese cyber operations have achieved a level of operational maturity that most defenders haven't yet adapted to. The reconnaissance-to-exploitation pipeline is now measured in hours, not weeks.
The hidden risk that most incident response plans miss: by the time you patch a vulnerability, the reconnaissance has already been completed. Threat actors using JDY have already identified which of your systems are vulnerable, mapped your network architecture, and determined your defensive posture. Your patch deployment becomes merely the defensive reaction to an intelligence operation that's already succeeded.
Defenders need to fundamentally shift their approach from "patch before we get attacked" to "assume we're already being scanned and reduce the value of that reconnaissance." That means network segmentation, assuming breach, reducing external attack surface, and building detection for the reconnaissance phase itself—not just the exploitation that follows.
Organizations in defense, energy, and government should review edge device inventory with fresh urgency. A forgotten SOHO router or unpatched managed switch isn't just a security incident waiting to happen; it's actively compromised infrastructure feeding adversarial intelligence right now.
— HackWire Editorial
## Related Coverage