ctipilot.ch

JDY botnet

campaign · campaign:jdy-botnet-volt-typhoon-2026

Volt Typhoon-linked JDY botnet expands to 1,500+ SOHO/IoT devices with sub-24-hour post-disclosure vulnerability scanning.

Coverage timeline
1
first 2026-06-11 → last 2026-06-11
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
3
pinned v19.1 · see below

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1590Gather Victim Network Information×1

Adversaries may gather information about the victim's networks that can be used during targeting. Information about networks may include a variety of details, including administrative data (ex: IP ranges, domain names, etc.) as well as specifics regarding its topology and operations.

Evidence: 2026-06-11/black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles · ATT&CK page ↗

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-06-11/black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles · ATT&CK page ↗

Resource Development TA0042

T1584.005Compromise Infrastructure: Botnet×1

Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems. Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers. With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS).

Evidence: 2026-06-11/black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles · ATT&CK page ↗

Story timeline

  1. 2026-06-11Black Lotus Labs: the Volt Typhoon-linked JDY botnet doubles to 1,500+ devices and weaponises CVE disclosures within hours
    research

Where this entity is cited

  • research1

Source distribution

  • lumen.com1 (50%)
  • thehackernews.com1 (50%)

explore in graph

Entries about JDY botnet (1)

2026-06-11 · view entry permalink →

NOTABLE

Black Lotus Labs: the Volt Typhoon-linked JDY botnet doubles to 1,500+ devices and weaponises CVE disclosures within hours

Lumen's Black Lotus Labs reports that the JDY botnet — the reconnaissance cluster that survived the 2024 KV-botnet takedown and is assessed with high confidence to support multiple China-nexus actors including Volt Typhoon — has more than doubled from roughly 650 bots in January 2024 to over 1,500 compromised SOHO and IoT devices (Lumen Black Lotus Labs, 2026-06-10). The botnet now spans Cisco, Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision and Linksys devices, performs multiprotocol service fingerprinting, banner-grabbing and TLS-certificate collection at scale, and routes C2 through hidden Tor services while managing victims with the open-source Platypus reverse-shell server. The operationally significant finding: scanning of Fortinet devices spiked within hours of the public disclosure of CVE-2026-35616, demonstrating sub-24-hour integration of new vulnerability intelligence into the recon-to-exploitation pipeline (The Hacker News, 2026-06-10). Targeting centres on US military and associated entities, with distributed European nodes. Technique mapping: T1595.002 Active Scanning: Vulnerability Scanning, T1590 Gather Victim Network Information, T1584.005 Compromise Infrastructure: Botnet.

Why it matters to us: JDY scanning should be treated as a precursor to targeted exploitation, not background noise — the sub-24-hour weaponisation window means CH/EU public-sector and critical-infrastructure operators must compress patch cycles for internet-facing edge appliances to hours, not weeks, after a disclosure. Hunt for outbound connections from edge/SOHO devices to the Platypus default service, unusual high-rate outbound SYN scanning, and unexpected TLS-certificate harvesting.

research11 Jun 05:00Zmulti-sourceOpen finding ↗