← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 15, 2026 · 07:00via The CyberWire

The botnet that scouts before it strikes. [Research Saturday]

Brief

Today we are joined by Ian Goldin , Senior Lead Information Security Engineer, and Mike Horka , Principal Information Security Engineer, from Lumen's Black Lotus Labs , discussing their research entitled "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation."

Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices.

The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U. S. military-related networks.

Read more on The CyberWire