JDY is a botnet and reconnaissance capability linked to Chinese state-sponsored threat actors. Initially associated with the KV-botnet, it later emerged as a distinct capability after disruption of KV in early 2024. JDY primarily compromises SOHO and IoT edge devices and uses them as a distributed platform for large-scale scanning, service fingerprinting, and mapping of exposed infrastructure. Its activity is oriented toward rapid identification of vulnerable systems, including shortly after public disclosure of new vulnerabilities, and the resulting telemetry supports downstream target selection and exploitation workflows. JDY operates through a covert management architecture that includes Tor-based infrastructure and command-and-control used to task bots for detailed system profiling. The malware can adapt its scanning behavior based on available privileges, using higher-performance SYN scanning when elevated privileges are present and falling back to standard TCP and TLS-based probing when they are not. Reported intrusion chains include exploitation of newly disclosed vulnerabilities in edge devices and delivery of a shell-script-based dropper to install the primary payload. The botnet has been observed at substantial scale across compromised networking and surveillance-related devices from multiple vendors. Its role is best characterized as industrialized reconnaissance rather than ransomware or disruptive operations, providing asset discovery and vulnerability-targeting support within a broader Chinese state-linked operational ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.