JDY is a China-nexus botnet and distributed reconnaissance platform associated with state-sponsored threat activity, including links to Volt Typhoon and the broader KV-botnet ecosystem. First identified as a scanning and reconnaissance cluster within KV in late 2023, JDY persisted after disruption of the main KV cluster and evolved into a distinct capability used to discover, fingerprint, and continuously map exposed internet-facing services at scale.
JDY primarily compromises SOHO, edge, and IoT devices, with early activity centered on Cisco RV320 and RV325 routers and later expansion to additional vendors including Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys. Infections are concentrated in the United States, with additional nodes observed across Europe, Asia, and the Americas. The use of legitimate residential and small-business infrastructure helps JDY blend malicious traffic into normal network activity and reduces the effectiveness of geofencing, IP reputation controls, and static blocklists.
The malware operates as a Linux scanning agent for MIPS-family embedded systems. A lightweight shell-script dropper checks device architecture, retrieves the appropriate payload, executes it, and removes itself from disk. Once running, JDY beacons to a central dispatch service, receives encrypted tasking and updated fingerprinting rules, performs multiprotocol probing and service identification, compresses collected results, and returns structured reconnaissance data to command infrastructure. Observed functionality includes banner collection, TLS certificate and metadata harvesting, protocol fingerprinting, and broad service discovery. When running with sufficient privileges, JDY can perform high-speed raw-socket SYN scanning; otherwise it falls back to slower TCP and TLS-based probing.
JDY command-and-control and payload infrastructure is managed through concealed Tor services, and some infected devices have been managed using the Platypus reverse-shell framework. The botnet is assessed to support targeted rather than indiscriminate scanning, with reporting indicating a strong focus on U.S. military and related networks. Operators have also been observed rapidly pivoting to newly disclosed vulnerabilities on edge infrastructure, indicating JDY functions as an upstream asset-discovery and vulnerability-targeting capability that feeds downstream exploitation workflows. Its continued operation and growth after partial takedowns demonstrate resilience as a durable reconnaissance capability within a broader Chinese state-aligned scanning ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Researchers at Black Lotus Labs have tracked a resurgence of the JDY botnet, a China-nexus network of compromised home and small-office devices... At its heart, the JDY botnet is a distributed scanning machine.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...increased exploitation activity against vulnerable SOHO devices directly exposed to the internet with the apparent target objective of expanding a botnet named “JDY” believed to be used by the threat actor for scanning/reconnaissance activity.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The report revealed that the botnet is intentionally used as a conduit to feed “structured reconnaissance data” into a broader Chinese state scanning infrastructure.
By distributing scanning and fingerprinting across thousands of compromised SOHO and IoT devices, operators can rapidly identify vulnerable infrastructure and targets of interest while evading traditional, IP-based defenses.
Several prominent cyber threat intelligence reports published in 2026 detail how Chinese state-sponsored threat actors are evolving their use of scanning and reconnaissance tools. Rather than relying on simple, indiscriminate network scans, these groups have industrialized their reconnaissance phase...
Black Lotus Labs found that JDY botnet operators target specific devices for scanning and reconnaissance, rather than conducting widespread, indiscriminate scanning. Most notably, there was a selective increase in scans of Fortinet equipment immediately after the disclosure of a new vulnerability, indicating the ability and intent to find and exploit vulnerable devices before patches are widely applied.
...with the apparent target objective of expanding a botnet named “JDY” believed to be used by the threat actor for scanning/reconnaissance activity.
Determine the device architecture by probing available system utilities and parsing command output... Once executed, the malware begins by initializing several variables, including a hardcoded malware version... and a unique “probe_id,” which is computed by MD5 hashing system-specific information.
Previous reports have noted that Volt Typhoon has used Tor for its C2 communications, so this traffic may reflect C2 communications between different Volt Typhoon-controlled resources...
Since infected devices are ordinary home and small business routers, their traffic blends in with normal internet activity, making detection harder for traditional security tools.
If this observation that 67.205.139[.]175 does not appear to have hosted a Tor exit node during the relevant timeframe is correct, it could be surmised that Volt Typhoon may not have leveraged Tor’s capability to connect to normal destinations on the internet... for obfuscating their source IP address while conducting administrative tasks.
Bots perform multiprotocol scans across TCP, UDP, SSL, and ICMP channels, then send compressed, encrypted results back to the central server.
A lightweight bash dropper handles infection: it detects the device’s processor type, downloads the matching payload, executes it, and deletes the file from disk.
Some devices are also managed through Platypus, an open-source remote shell tool, with the payload server at 149.248.3[.]38 hosting a Platypus instance on port 13339.
Infected devices receive scanning tasks from a command-and-control server communicating via hidden Tor nodes, making it nearly impossible to trace back to operators. Bots perform multiprotocol scans across TCP, UDP, SSL, and ICMP channels, then send compressed, encrypted results back to the central server.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux-based scanning botnet targeting MIPS routers and embedded devices. It uses compromised SOHO/edge devices to perform distributed reconnaissance, collect service banners and TLS certificates, and rapidly scan for newly disclosed vulnerabilities via encrypted tasking from command-and-control infrastructure.
A botnet targeting unpatched routers, cameras, SOHO, edge, and IoT devices. It is used primarily for scanning, fingerprinting, and reconnaissance to identify exposed services and vulnerable infrastructure for later exploitation.
A China-linked botnet operating on compromised SOHO and IoT devices to conduct internet-wide reconnaissance and vulnerability scanning, then return encrypted scan results to command-and-control infrastructure for use by China-aligned threat actors. It uses Linux payloads for MIPS/MIPSEL architectures, a bash dropper, Tor-hidden C2, and can leverage Platypus for remote shell management.
A centrally controlled, high-performance IoT/SOHO botnet used for infrastructure reconnaissance. It discovers, fingerprints, and continuously maps exposed services at scale, sending structured reconnaissance data back to operators to support follow-on targeting and exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.