JDY is a Linux-based reconnaissance botnet associated with China-nexus state-sponsored activity, including Volt Typhoon. Publicly identified in 2023 as a scanning cluster within the KV-botnet ecosystem, it remained operational after disruption of the companion KV cluster in late 2023 and early 2024. By June 2026, JDY had expanded from approximately 650 active devices in January 2024 to more than 1,500 compromised small-office/home-office and IoT devices across the Americas, Europe, and Asia, with a substantial concentration in the United States. Its reconnaissance activity has shown a pronounced focus on U.S. military and associated networks.
JDY runs on MIPS-family routers and embedded systems, including devices from Cisco, Araknis, Mimosa Networks, Ubiquiti, DrayTek, Hikvision, and Linksys. Infection chains exploit vulnerable internet-exposed edge devices and deploy a shell-script dropper that selects an architecture-compatible payload, launches it, and removes the downloaded binary from disk. Operators use concealed Tor-based management infrastructure, and some compromised devices are additionally managed through the Platypus reverse-shell framework.
The malware registers with a centralized dispatch service, reports host characteristics, and receives encrypted scanning assignments and downloadable service-fingerprinting rules. It supports TCP, TLS, UDP, and ICMP-assisted probing, collecting service banners, certificate metadata, protocol characteristics, and web responses. When sufficient privileges permit raw sockets, it performs high-speed SYN scanning; otherwise, it falls back to conventional connections. Structured reconnaissance results are compressed and returned to command-and-control infrastructure.
JDY primarily supplies asset-discovery and vulnerability-targeting intelligence for follow-on operations rather than directly exploiting scanned targets. Its operators rapidly redirect scanning toward newly disclosed vulnerabilities. Distributing reconnaissance across compromised residential and small-business devices helps blend malicious traffic with legitimate activity and evade geofencing, reputation filters, and static blocklists.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Researchers at Black Lotus Labs have tracked a resurgence of the JDY botnet, a China-nexus network of compromised home and small-office devices... At its heart, the JDY botnet is a distributed scanning machine.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...increased exploitation activity against vulnerable SOHO devices directly exposed to the internet with the apparent target objective of expanding a botnet named “JDY” believed to be used by the threat actor for scanning/reconnaissance activity.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The report revealed that the botnet is intentionally used as a conduit to feed “structured reconnaissance data” into a broader Chinese state scanning infrastructure.
By distributing scanning and fingerprinting across thousands of compromised SOHO and IoT devices, operators can rapidly identify vulnerable infrastructure and targets of interest while evading traditional, IP-based defenses.
Several prominent cyber threat intelligence reports published in 2026 detail how Chinese state-sponsored threat actors are evolving their use of scanning and reconnaissance tools. Rather than relying on simple, indiscriminate network scans, these groups have industrialized their reconnaissance phase...
Black Lotus Labs found that JDY botnet operators target specific devices for scanning and reconnaissance, rather than conducting widespread, indiscriminate scanning. Most notably, there was a selective increase in scans of Fortinet equipment immediately after the disclosure of a new vulnerability, indicating the ability and intent to find and exploit vulnerable devices before patches are widely applied.
...with the apparent target objective of expanding a botnet named “JDY” believed to be used by the threat actor for scanning/reconnaissance activity.
Determine the device architecture by probing available system utilities and parsing command output... Once executed, the malware begins by initializing several variables, including a hardcoded malware version... and a unique “probe_id,” which is computed by MD5 hashing system-specific information.
Previous reports have noted that Volt Typhoon has used Tor for its C2 communications, so this traffic may reflect C2 communications between different Volt Typhoon-controlled resources...
Since infected devices are ordinary home and small business routers, their traffic blends in with normal internet activity, making detection harder for traditional security tools.
If this observation that 67.205.139[.]175 does not appear to have hosted a Tor exit node during the relevant timeframe is correct, it could be surmised that Volt Typhoon may not have leveraged Tor’s capability to connect to normal destinations on the internet... for obfuscating their source IP address while conducting administrative tasks.
Bots perform multiprotocol scans across TCP, UDP, SSL, and ICMP channels, then send compressed, encrypted results back to the central server.
A lightweight bash dropper handles infection: it detects the device’s processor type, downloads the matching payload, executes it, and deletes the file from disk.
Some devices are also managed through Platypus, an open-source remote shell tool, with the payload server at 149.248.3[.]38 hosting a Platypus instance on port 13339.
Infected devices receive scanning tasks from a command-and-control server communicating via hidden Tor nodes, making it nearly impossible to trace back to operators. Bots perform multiprotocol scans across TCP, UDP, SSL, and ICMP channels, then send compressed, encrypted results back to the central server.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux-based scanning botnet targeting MIPS routers and embedded devices. It uses compromised SOHO/edge devices to perform distributed reconnaissance, collect service banners and TLS certificates, and rapidly scan for newly disclosed vulnerabilities via encrypted tasking from command-and-control infrastructure.
A botnet targeting unpatched routers, cameras, SOHO, edge, and IoT devices. It is used primarily for scanning, fingerprinting, and reconnaissance to identify exposed services and vulnerable infrastructure for later exploitation.
A China-linked botnet operating on compromised SOHO and IoT devices to conduct internet-wide reconnaissance and vulnerability scanning, then return encrypted scan results to command-and-control infrastructure for use by China-aligned threat actors. It uses Linux payloads for MIPS/MIPSEL architectures, a bash dropper, Tor-hidden C2, and can leverage Platypus for remote shell management.
A centrally controlled, high-performance IoT/SOHO botnet used for infrastructure reconnaissance. It discovers, fingerprints, and continuously maps exposed services at scale, sending structured reconnaissance data back to operators to support follow-on targeting and exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.