CyberWire Daily - The botnet that scouts before it strikes. [Research Saturday]

Episode Date: August 15, 2026

Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled... "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call. But Dopple sees through the disguise. Their AI-native platform detects and disrupts attacks across every channel, trains employees to recognize deepfakes and deception, and investigates every fish to take down the campaign behind it. They fight relentlessly to protect you. your business, brand, and people. Doppel, outpacing what's next in social engineering.
Starting point is 00:00:43 Learn more at Doppel.com. That's D-O-P-P-P-E-L.com. Hello everyone and welcome to the CyberWire's Research Saturday. I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in a rapidly evolving cyberspace. Thanks for joining us. And actually recently we observed a resurgence of this JDIY botnet, and it's expanded in a couple of different ways. And that's really what prompted us to start digging into it again and put out the research that is the subject of this blog. That's Ian Golden, senior lead information security engineer, along with Mike Horka, principal information security engineer from Lumen's Black Lotus Labs.
Starting point is 00:01:53 They'll both be discussing their research entitled Expanded JDIY IOT and SoHo Botnet enables rapid vulnerability exploitation. So this story goes back a couple of years. It involves Chinese APTs and cyber espionage. So it's actually not a new network. A few years ago, we published some research on another network called the KV botnet. And the KV botnet was important because it was linked to. Volt Typhoon, which is, of course, the infamous Chinese APT responsible for targeting critical infrastructure providers. And at the time, the KV Botnet was used as a covert network. And you'll hear this term sometimes also referred to as an orb network or operational relay box network, but they're basically groups of devices, sometimes compromised devices that adversaries use
Starting point is 00:02:55 to relay and proxy their traffic, to obfuscate who they are, where they're coming from, and basically it helps them blend in with normal traffic. And so when we were doing our research on the KV botnet, we noticed it had kind of two main clusters.
Starting point is 00:03:10 There was the KV side, which was sort of a covert data transfer network. And then the other side was, we called it the JDIY cluster, and it was used for reconnaissance and targeting. The KV side of the network, was disrupted by a law enforcement takedown a couple of years ago and has been pretty defunct since then.
Starting point is 00:03:33 But the J.D.Y side, the reconnaissance part, has never gone away. And actually recently we observed a resurgence of this JDIY botnet, and it's expanded in a couple of different ways. And that's really what prompted us to start digging into it again and put out the research that is the subject of this blog. Michael, I'm curious, when did you all realize that this wasn't just a botnet that had survived those earlier takedowns, but one that had actually grown into something a bit more capable? You know, initially it was definitely size. The botnet or the JDIY cluster that we were tracking during the days of KV botnet was more, I would call it more small scale. I think the peak that we would see was maybe 750, 800 bots.
Starting point is 00:04:25 or infected nodes that were checking into that cluster, but more recently that had at least doubled, and we were seeing an increase in scanning activity and probing activity coming out of that cluster. One of the things that struck me when I was going through the research was how much diversity there is in the compromised devices. Why would the threat actor expand beyond just a few router models to all these different Soho and IoT devices. Ian?
Starting point is 00:04:58 Yeah, I think the short answer is that it makes it harder to track and block these devices. So like you said, initially years ago, it was basically two Cisco router models that they were using. And more recently, it's essentially doubled in size. There are now more than 1,500 compromised bots that are part of this network. And in addition to the increase in size, we're also seeing a diversification of device types like you mentioned. So we're seeing other vendors being exploited like ubiquity, HickVision, Lynxys, you know, kind of the typical Soho and IoT device types that you often see in botnets. And, you know, the advantage that that gives the threat actors is essentially, you know, it's scale plus diversity. again, it makes it harder to detect and block.
Starting point is 00:05:51 It gives them more options. It helps them blend in with different kinds of traffic, and it makes it harder to take down. If there is another law enforcement takedown effort, it just gives them more places to hide. Michael, the research describes J.D.Y primarily as a reconnaissance platform rather than an exploitation platform. Can you help us understand the difference there
Starting point is 00:06:16 and why reconnaissance is valuable for an advanced threat actor? Yeah, absolutely. Yeah, so we do retract JDIY more generally as a scalable reconnaissance botnet. Its primary purpose is not pure exploitation or data theft or launching DDoS attacks. That's very commonly understood for the botnet terminology. Instead, JDIY's primary purpose was to identify exposed services, fingerprint devices, and servers, and then rapidly, rapidly, locate vulnerable infrastructure.
Starting point is 00:06:48 So this particular type of telemetry that they're able to gather is we would assess fed back into a back-end intelligence collection database where then multiple China Nexus threat actors can parse, query, and filter through this data to guide their follow-on malicious activity. So how is that useful? You can kind of think about, you know, JDIY as being like the initial scout, and its job isn't necessarily to attack the target, but its job is to identify lock doors, open windows, and fingerprint them in a way to provide enough information when they come back to report back into this database. So then you've got a follow-on malicious phone actors who can take that information and action it in some way.
Starting point is 00:07:28 Well, if I owned one of these infected routers, what would it be spending its time doing? And would I even notice? In a distributed fashion, perhaps not. And that's part of the benefit to the operators of this botnet in expanding. two 1,500 and more compromised devices is that you aren't spreading out that load across all of those devices. So as a home user with a home router that may be compromised, you know, maybe initially when you're one of 50 or 100 bots in the network, you may notice a spike in your bandwidth or an unresponsive home router on a regular basis. But when you've got this distributed across
Starting point is 00:08:14 thousands of nodes, it's far less likely that you're even going to notice as a home user. You know, the research talks about how the malware doesn't just scan everything indiscriminately. It's pretty selective in what it's doing. Ian, what's the significance of that? Yeah, that's really important. There's definitely intentional targeting, but it's also at scale. So, you know, some of these nodes are scanning hundreds of thousands of target IP addresses at a time. But it's not indiscriminate.
Starting point is 00:08:46 It's not scanning the entire internet. It's not a replacement for something like census or chodun, these websites that basically scan and index the internet. There was a pretty strong focus on organizations that seem to align with Chinese geopolitical interests. So, for example, organizations that are related to the military. And that kind of reinforces the idea that this, is part of a broader intelligence collection and exploitation pipeline. The point that Mike made earlier about the difference between reconnaissance and exploitation
Starting point is 00:09:23 is really critical. We think this is one piece of the puzzle. And so one of the really interesting things we saw was, so back in April, there was a new Fortnite vulnerability that was disclosed. I think it was a CVSS score of 9.8. So critical vulnerability. And basically within hours of the disclosure of that CVE, we saw a significant spike of scanning from the JDIB bots against Ftinent devices.
Starting point is 00:09:54 So clearly, the threat actor is monitoring for new vulnerabilities as they're released, and then essentially tasking this botnet to go out and look for vulnerable devices that might be vulnerable to that CVE. So it's not random or indiscriminate. it's targeted in a couple different key ways. And again, that speaks to the fact or our assessment that this is one part of kind of this larger exploitation pipeline. Does this suggest that reconnaissance has become kind of an industrialized process where these vulnerabilities get identified and maybe queued up for follow-on operations really quickly? I mean, the research really
Starting point is 00:10:38 highlights the speed of exploitation here. Absolutely. I think one of the key takeaways for defenders, you know, reconnaissance is happening continuously and exploitation is happening continuously and they're happening at scale. And, you know, of course, now with AI, they're happening faster than ever before. And that's really the difference that we're dealing with today, you know, has the potential to give adversaries the upper hand. And so, you know, defenders are just going to have to be faster. They're going to have to be faster at prioritizing and patching new vulnerabilities, especially for internet-facing devices. And when intrusions do happen, they're going to have to be faster at detecting them and responding to them.
Starting point is 00:11:22 This is why we have concepts like zero trust and assume breach. If a single edge device is compromised, that really shouldn't, ideally should not result in the compromise of your entire network, doesn't have to result in a data breach. You know, those core concepts or something that I think we have to get back to sort of brilliance and the basics to deal with this kind of problem. We'll be right back. The research notes that many of these compromised devices are located in the United States. Michael, what's the significance of that in terms of making them easy or difficult to detect
Starting point is 00:12:09 or block? Yeah, I mean, it definitely makes it, you know, like the geographical location of a lot of the bots in a lot of the botanets to be tracked not just JDI. It's rarely by chance a lot of times we will see that there will be larger numbers of nodes in regions that China has a strategic interest in targeting. You know we've seen that in previous bot nets like Raptor Train. Raptor Train was a good example where we saw a more even-heeled distribution of US and Taiwan-based bots or nodes that were a part of that bot net and that was in direct alignment with the type of targeting we observed against
Starting point is 00:12:50 US and Taekwini's entities out of that network. The same applies here with with JDI. So, you know, we obviously have a higher frequency of U.S.-based bots and it's, you know, very likely not a not a coincidence that we're seeing that align almost directly with the type of U.S.-based targeting that we see for this, this purving and scanning activity. Definitely. And, you know, to add to Mike's point, One implication of that is it makes traditional IP-based defenses like geo-fencing a little bit less effective. So some of your listeners might have controls that you might block connections from IPs in countries like China or Russia. But in this case, a lot of the IP addresses are in the United States.
Starting point is 00:13:37 And so they're not coming from China or Russia. They look like they're coming from a residential IP space in Ohio or a mom-and-pop law firm. in Texas. So it helps the threat actors blend into traditional or legitimate user traffic. It really highlights the need to move beyond those kind of traditional IP-based defenses and you need to start incorporating better cyber threat intelligence and sort of more behavioral controls. Can we dig into that for just a second? I mean, what makes malicious reconnaissance from a home router look so much like legitimate traffic. Help me understand that strategy. So one strategy that is pretty common in enterprise environments, you might block connections
Starting point is 00:14:24 from known VPN providers or known data center IP addresses. You know, you can distinguish pretty easily with IP enrichment between residential IP space and data center IP space. And I know that if a data center is scanning me, it's a little bit more suspicious. because that's likely someone that has set up some sort of automated. They could be trying to brute force your VPN or scan your website. It's just, it sticks out a little bit more for the defenders. But when you have activity coming from residential IP space, it just makes it a little bit harder to filter out and to block.
Starting point is 00:15:03 I'm curious from a technical point of view, was there anything outstanding or interesting in your analysis here, anything that set this apart from things you'd seen before. Purely from like a capabilities standpoint for what JDI was able to do, you know, it had some pretty intense like multi-protigal. It was able to do banner grabs and service grabs and then also fingerprint those. So it had follow-on filters that it was able to apply. So it was able to kind of ignore, you know, generic filters or generic banner responses
Starting point is 00:15:38 that it would receive, which is basically just a, it's a, it's a, way of saying that they were able to do like a fingerprinting plus on top of like a service that they're able to provide back to whoever is consuming their scan results on the back end. As part of their TLS certificate collection that they were doing, they were able to, consumers of this data would be able to identify domain names or specific targets, specific domains attached to those TLS certificates. And then you also had the vulnerability driven programming that Ian already talked about, which is, you know, this network was pivoting so quickly on recent vulnerabilities as they're announced.
Starting point is 00:16:17 So, again, from like a consumer standpoint of someone who would be looking through this data, they're getting, you know, near real time, within hours of vulnerabilities being released, very specific, attributed, and detailed results on, you know, on, let's use the Fortinet vulnerability, for example, on all the Fortnite devices in very high-profile sector. in the U.S., potentially within maybe three to six hours after vulnerability was released. And that type of turnaround time, that speed, is probably one of the more concerning aspects of something like JDI. You know, so speed and scale, we talked about the scale as well, but speed in particular,
Starting point is 00:16:58 that turnaround time, but then scale on the fact that they're able to do this near surreptitiously because of the spread across thousands of software devices, they're able to feedback this data wanted to do without being noticed. Yeah, one of the things that caught my eye was you all highlighted the adaptability of the malware, that depending on the level of access that it had on a particular compromise device, it would behave differently. That struck me as being an interesting design choice. Can you explain that to us?
Starting point is 00:17:32 So one interesting aspect of this malware is that if it had... route or admin privileges on the target device, then it was able to open up a raw socket, TCP socket, and create a custom TCP packet to allow the malware to launch SIN scans against its targets. And those SIN scans basically allow really rapid scanning, and it also prevents application level logging on the target end.
Starting point is 00:18:09 If it did not have root privileges or if it was conducting a web scan, then it would just use the normal TCP stack to basically enumerate the services that Mike talked about. So grab things like TLS certificates and service banners and things like that. Mike, anything else that caught your eye? I mean, I guess just to add on
Starting point is 00:18:37 to what you just said. I mean, the, another, another thing that, uh, that benefits for the threat actors is the overall noise reduction in bandwidth limitations of,
Starting point is 00:18:47 or bypassing bandwidth limitations on home routers. It's, you know, obviously that's a something we talked about where, you know, would a home user notice if their bandwidth spike because their home router is scanning, essentially scanning thousands or tens of thousands of,
Starting point is 00:19:00 um, servers out on the internet. Uh, and perhaps if they were doing full TSP handshakes. and hitting tens of thousands of nodes, but when they're doing pure sin scanning, like Gaines described, where they could do it through the raw socket,
Starting point is 00:19:14 that, again, just allows them to do it more scalably, but also remain extremely stealthy. Looking at the big picture here, what is your sense? I mean, is this the shape of things to come where adversaries maintain these standing reconnaissance platforms so that they're always ready when the next vulnerability is announced?
Starting point is 00:19:37 Yeah. Definitely. I think, you know, reconnaissance is becoming industrialized at scale, kind of like we talked about earlier. You know, I think defenders, sometimes we tend to neglect reconnaissance. You know, you often don't really hear about it. And, you know, reading a threat intelligence report or an incident response report, you might not see very much on the recon side. But there's a reason why it's the first step in the cyber kill chain. You can't exploit a vulnerable device or service.
Starting point is 00:20:11 If you don't know, it exists. And I think a lot of offensive security professionals, red teamers and pen testers, would probably agree that reconnaissance is one of, if not the most important step in the process. And so there's a sort of asymmetry there. It's really important for attackers, but kind of neglected by defenders. And this research shows that it's becoming a sort of foundation. part of, oh, it was already a part of a foundational part of sort of nation, state level activity, but it's only becoming more so. And it's, again, becoming industrialized. It's
Starting point is 00:20:50 happening at scale. It's happening faster and faster than ever before. So this is something that we might need to start paying a little bit more attention to. Michael, any additional thoughts on that? Yeah, I mean, I think we are definitely seeing industrialization and commercialization of network infrastructure across the board. I would say, I mean, we talk a lot about botnets, obfuscation networks. We've put out several blog posts on a few of those and discussed orb networks,
Starting point is 00:21:18 proxy networks. You know, all of those are, not all of them, but a good portion of them are servicing multiple, malicious threat actors that are operating over them to enable their operations. And so you have JDI involved in that first step of the cyber kill chain, reconnaissance. You've also got, you know,
Starting point is 00:21:35 There's weaponization and delivery after that, and that starts leading into exploitation. And we're seeing that, you know, just across the board, for almost every step of the cyber kill chain at this point, we're seeing different aspects of it being industrialized through shared orb networks, commercialization, through shared scanning and probing results, fingerprinting databases. You know, we're also seeing a lot of shared malware across threat actors. It kind of used to be that threat actors would maintain a tight hold on, on a lot of the custom malware and you start seeing that more and more with the shared malware, or even just, you know, off-the-shelf tools that they can get freely available on GitHub
Starting point is 00:22:15 that are being shared across the board. So there's absolutely a just a full industrialization of a large portion of the cycle chain at this point we're observing. For the security folks in our audience, the people who are tasked with defending their own organizations. Based on the research you all have put together here, what are your recommendations? I think there are kind of two categories of recommendations. First, for listeners at home or if you're in a small business, you want to make sure that your router doesn't end up compromised and a part of this botnet. So basic cyber hygiene is important. You want to make sure that you're not using old end-of-life routers or IoT devices and make sure that they're updated and that you apply
Starting point is 00:23:02 patches regularly and occasionally reboot those devices. And the second category is, you know, for the larger organizations who might actually be targeted by the reconnaissance activity itself, I think the two main recommendations, the priorities are really to, one, reduce your external attack service, anything exposed to the internet as much as possible. And then two, you're going to have to establish a vulnerability program that prioritizes patching, especially for internet-facing devices. There are more recommendations in the SISA and UK government reports that we link to in our blog. A lot of them come down to kind of the foundational security controls that are often easier
Starting point is 00:23:47 said than done. Things like hardening attack surface and securing credentials. Again, the sort of foundational zero-trust type policies that we need to get better at to deal with some of these actors like Bull Typhoon who are using living off the land techniques and leveraging these kinds of covert devices. Our thanks to Ian Golden and Mike Horka of Lumen's Black Lotus Labs,
Starting point is 00:24:26 we'll have a link to their research entitled Expanded JDIYIOTE and Soho Botnet enables rapid vulnerability exploitation in the show notes. And that's Research Saturday, brought to you by N2K Cyberwire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead
Starting point is 00:24:46 in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com. This episode was produced by Liz Stokes.
Starting point is 00:25:04 We're mixed by Elliot Peltzman and Trey Hester. Our executive producer is Jennifer Ibin. Peter Kilpie is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here next time.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.