JDY botnet reconnaissance expansion to 1,500+ SOHO/IoT devices
Malware Activity
Summary
Hide ▲
Show ▼
The JDY botnet has expanded to more than 1,500 compromised SOHO/IoT devices, making it a larger-scale reconnaissance scanner for exposed infrastructure and follow-on targeting. It now performs targeted scanning and service fingerprinting through a centrally controlled command structure, which increases its value as a discovery layer for attackers. The network’s growth from 650 bots in early January 2024 and its spread across the U.S., Brazil, Europe, and Asia broaden its reach and resilience. Its scan results feed downstream exploitation pipelines, giving operators timely targeting data after vulnerability disclosures.
Related Happenings
CISA warning on FortiBleed for FortiGate customers
Public Sector Action
H score89
First: 19.06.2026 17:00
Last: 19.06.2026 17:00
Sources 1
About this happening:
CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
CISA warning on FortiBleed for FortiGate customers
Public Sector ActionAbout this happening: CISA warned Fortinet customers with FortiGate appliances to secure exposed systems against ongoing malicious activity tied to FortiBleed. The activity had reached...
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
Campaign
H score36
First: 21.05.2026 17:00
Last: 21.05.2026 17:00
Sources 1
About this happening:
A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
Calypso telecommunications espionage campaign using Showboat and JFMBackdoor
CampaignAbout this happening: A Calypso / Red Lamassu espionage campaign is targeting telecommunications providers with new Showboat and JFMBackdoor malware, increasing the risk of long-term co...
OpenAI launches Daybreak cybersecurity initiative for AI-powered vulnerability detection and patch validation
Security Tool/Service
H score25
First: 12.05.2026 09:55
Last: 12.05.2026 09:55
Sources 1
About this happening:
OpenAI's Daybreak launch adds an AI-powered cybersecurity service for vulnerability detection and patch validation, helping organizations fix flaws before attacker...
OpenAI launches Daybreak cybersecurity initiative for AI-powered vulnerability detection and patch validation
Security Tool/ServiceAbout this happening: OpenAI's Daybreak launch adds an AI-powered cybersecurity service for vulnerability detection and patch validation, helping organizations fix flaws before attacker...
China-nexus hijacked-device proxy network campaign
Campaign
H score43
First: 23.04.2026 15:28
Last: 23.04.2026 15:28
Sources 1
How related:
the stealthy network comprising compromised SOHO routers, firewalls, and IoT devices has been put to use by Chinese hacking groups like Volt Typhoon.
About this happening:
NCSC-UK and international partners warned on 2026-04-23 that China-nexus hackers are using large-scale proxy networks built from hijacked consumer devices, including *...
China-nexus hijacked-device proxy network campaign
CampaignHow related: the stealthy network comprising compromised SOHO routers, firewalls, and IoT devices has been put to use by Chinese hacking groups like Volt Typhoon.
About this happening: NCSC-UK and international partners warned on 2026-04-23 that China-nexus hackers are using large-scale proxy networks built from hijacked consumer devices, including *...
SocksEscort criminal proxy-service ecosystem monetizing residential routers
Threat Actor Meta
H score36
First: 13.03.2026 07:26
Last: 13.03.2026 07:26
Sources 1
About this happening:
The SocksEscort proxy-service ecosystem turned compromised residential routers into a rentable abuse platform, letting criminal customers hide behind 369,000 IP addresses...
SocksEscort criminal proxy-service ecosystem monetizing residential routers
Threat Actor MetaAbout this happening: The SocksEscort proxy-service ecosystem turned compromised residential routers into a rentable abuse platform, letting criminal customers hide behind 369,000 IP addresses...
Timeline
-
10.06.2026 19:08 2 articles · 1mo ago
Initial report: JDY botnet reconnaissance expansion to 1,500+ SOHO/IoT devices
Initial DisclosureThe JDY cluster first emerged inside KV-botnet in mid-December 2023, before the broader network was disrupted in early 2024. After that takedown, the operators kept the reconnaissance capability alive and expanded it beyond the original router-heavy footprint.
Show sources
- China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance — thehackernews.com — 10.06.2026 19:08
- China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance — thehackernews.com — 10.06.2026 19:08