Security/ botnet · china · iot security · vulnerability scanning

China-Linked Botnet Doubles to 1,500 Routers, Scans Flaws in Hours

The JDY botnet has more than doubled to 1,500 compromised routers and IoT devices, and begins probing newly disclosed vulnerabilities within hours of publication.

China-Linked Botnet Doubles to 1,500 Routers, Scans Flaws in Hours

A botnet tied to Chinese state-sponsored hackers has quietly doubled in size and is now racing to probe newly disclosed vulnerabilities before defenders can patch them.

Researchers at Lumen's Black Lotus Labs published findings this week tracking the JDY botnet, which now comprises more than 1,500 compromised small office and home office routers, firewalls, and IoT devices — more than double its previous footprint. The operators begin scanning for newly disclosed vulnerabilities within hours of public disclosure, a timeline that collapses the window between "known flaw" and "active target" to near zero. The devices feeding the botnet are the kind that sit forgotten at network edges: rarely patched, often running end-of-life firmware, and exposed to the public internet by design.

Speed is the threat model here. Most enterprise patching cycles run days to weeks; an adversary that starts probing within hours is effectively treating published CVEs as a prioritized work queue. SOHO routers have become the preferred raw material for Chinese state-linked operations — Volt Typhoon used comparable compromised-device infrastructure in 2023 to pre-position inside U.S. critical networks — which suggests JDY is less about opportunistic exploitation and more about systematic terrain mapping.

A 1,500-node botnet is modest by spam-ring standards, but a tightly controlled reconnaissance platform built to chart Western network exposure is a different threat category than sheer scale.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →