CyberWire Daily - The botnet that scouts before it strikes. [Research Saturday]
Episode Date: August 15, 2026Today we are joined by Ian Goldin, Senior Lead Information Security Engineer, and Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs, discussing their research entitled... "Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation." Black Lotus Labs has uncovered a major resurgence of the JDY botnet, a China-nexus reconnaissance network now comprising more than 1,500 compromised SOHO and IoT devices. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The research and executive brief can be found here: Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call.
But Dopple sees through the disguise.
Their AI-native platform detects and disrupts attacks across every channel,
trains employees to recognize deepfakes and deception,
and investigates every fish to take down the campaign behind it.
They fight relentlessly to protect you.
your business, brand, and people. Doppel, outpacing what's next in social engineering.
Learn more at Doppel.com. That's D-O-P-P-P-E-L.com.
Hello everyone and welcome to the CyberWire's Research Saturday. I'm Dave Bittner,
and this is our weekly conversation with researchers and analysts tracking down the threats
and vulnerabilities, solving some of the hard problems and protecting ourselves in a rapidly
evolving cyberspace. Thanks for joining us.
And actually recently we observed a resurgence of this JDIY botnet, and it's expanded in a couple of different ways.
And that's really what prompted us to start digging into it again and put out the research that is the subject of this blog.
That's Ian Golden, senior lead information security engineer, along with Mike Horka, principal information security engineer from Lumen's Black Lotus Labs.
They'll both be discussing their research entitled Expanded JDIY IOT and SoHo Botnet enables rapid vulnerability exploitation.
So this story goes back a couple of years. It involves Chinese APTs and cyber espionage.
So it's actually not a new network. A few years ago, we published some research on another network called the KV botnet.
And the KV botnet was important because it was linked to.
Volt Typhoon, which is, of course, the infamous Chinese APT responsible for targeting critical
infrastructure providers. And at the time, the KV Botnet was used as a covert network. And you'll
hear this term sometimes also referred to as an orb network or operational relay box network,
but they're basically groups of devices, sometimes compromised devices that adversaries use
to relay and proxy their traffic,
to obfuscate who they are,
where they're coming from,
and basically it helps them blend in
with normal traffic.
And so when we were doing our research
on the KV botnet,
we noticed it had kind of two main clusters.
There was the KV side,
which was sort of a covert data transfer network.
And then the other side was,
we called it the JDIY cluster,
and it was used for reconnaissance and targeting.
The KV side of the network,
was disrupted by a law enforcement takedown a couple of years ago
and has been pretty defunct since then.
But the J.D.Y side, the reconnaissance part, has never gone away.
And actually recently we observed a resurgence of this JDIY botnet,
and it's expanded in a couple of different ways.
And that's really what prompted us to start digging into it again
and put out the research that is the subject of this blog.
Michael, I'm curious, when did you all realize that this wasn't just a botnet that had survived those earlier takedowns, but one that had actually grown into something a bit more capable?
You know, initially it was definitely size. The botnet or the JDIY cluster that we were tracking during the days of KV botnet was more, I would call it more small scale.
I think the peak that we would see was maybe 750, 800 bots.
or infected nodes that were checking into that cluster,
but more recently that had at least doubled,
and we were seeing an increase in scanning activity
and probing activity coming out of that cluster.
One of the things that struck me when I was going through the research
was how much diversity there is in the compromised devices.
Why would the threat actor expand beyond just a few router models
to all these different Soho and IoT devices. Ian?
Yeah, I think the short answer is that it makes it harder to track and block these devices.
So like you said, initially years ago, it was basically two Cisco router models that they were using.
And more recently, it's essentially doubled in size.
There are now more than 1,500 compromised bots that are part of this network.
And in addition to the increase in size, we're also seeing a diversification of device types like you mentioned.
So we're seeing other vendors being exploited like ubiquity, HickVision, Lynxys, you know, kind of the typical Soho and IoT device types that you often see in botnets.
And, you know, the advantage that that gives the threat actors is essentially, you know, it's scale plus diversity.
again, it makes it harder to detect and block.
It gives them more options.
It helps them blend in with different kinds of traffic,
and it makes it harder to take down.
If there is another law enforcement takedown effort,
it just gives them more places to hide.
Michael, the research describes J.D.Y primarily as a reconnaissance platform
rather than an exploitation platform.
Can you help us understand the difference there
and why reconnaissance is valuable for an advanced threat actor?
Yeah, absolutely.
Yeah, so we do retract JDIY more generally as a scalable reconnaissance botnet.
Its primary purpose is not pure exploitation or data theft or launching DDoS attacks.
That's very commonly understood for the botnet terminology.
Instead, JDIY's primary purpose was to identify exposed services,
fingerprint devices, and servers, and then rapidly, rapidly,
locate vulnerable infrastructure.
So this particular type of telemetry that they're able to gather is we would assess fed
back into a back-end intelligence collection database where then multiple China Nexus threat actors
can parse, query, and filter through this data to guide their follow-on malicious activity.
So how is that useful?
You can kind of think about, you know, JDIY as being like the initial scout, and its job isn't
necessarily to attack the target, but its job is to identify lock doors, open windows,
and fingerprint them in a way to provide enough information when they come back to report back into this database.
So then you've got a follow-on malicious phone actors who can take that information and action it in some way.
Well, if I owned one of these infected routers, what would it be spending its time doing?
And would I even notice?
In a distributed fashion, perhaps not.
And that's part of the benefit to the operators of this botnet in expanding.
two 1,500 and more compromised devices is that you aren't spreading out that load across all of those
devices. So as a home user with a home router that may be compromised, you know, maybe initially
when you're one of 50 or 100 bots in the network, you may notice a spike in your bandwidth
or an unresponsive home router on a regular basis. But when you've got this distributed across
thousands of nodes, it's far less likely that you're even going to notice as a home user.
You know, the research talks about how the malware doesn't just scan everything indiscriminately.
It's pretty selective in what it's doing.
Ian, what's the significance of that?
Yeah, that's really important.
There's definitely intentional targeting, but it's also at scale.
So, you know, some of these nodes are scanning hundreds of thousands of target IP addresses at a time.
But it's not indiscriminate.
It's not scanning the entire internet.
It's not a replacement for something like census or chodun,
these websites that basically scan and index the internet.
There was a pretty strong focus on organizations that seem to align with Chinese geopolitical interests.
So, for example, organizations that are related to the military.
And that kind of reinforces the idea that this,
is part of a broader intelligence collection and exploitation pipeline.
The point that Mike made earlier about the difference between reconnaissance and exploitation
is really critical.
We think this is one piece of the puzzle.
And so one of the really interesting things we saw was, so back in April, there was a
new Fortnite vulnerability that was disclosed.
I think it was a CVSS score of 9.8.
So critical vulnerability.
And basically within hours of the disclosure of that CVE,
we saw a significant spike of scanning from the JDIB bots against Ftinent devices.
So clearly, the threat actor is monitoring for new vulnerabilities as they're released,
and then essentially tasking this botnet to go out and look for vulnerable devices
that might be vulnerable to that CVE.
So it's not random or indiscriminate.
it's targeted in a couple different key ways. And again, that speaks to the fact or our assessment
that this is one part of kind of this larger exploitation pipeline. Does this suggest that
reconnaissance has become kind of an industrialized process where these vulnerabilities get
identified and maybe queued up for follow-on operations really quickly? I mean, the research really
highlights the speed of exploitation here. Absolutely. I think one of the key takeaways for defenders,
you know, reconnaissance is happening continuously and exploitation is happening continuously and they're
happening at scale. And, you know, of course, now with AI, they're happening faster than ever before.
And that's really the difference that we're dealing with today, you know, has the potential to give
adversaries the upper hand. And so, you know, defenders are just going to have to be faster.
They're going to have to be faster at prioritizing and patching new vulnerabilities,
especially for internet-facing devices.
And when intrusions do happen, they're going to have to be faster at detecting them and responding to them.
This is why we have concepts like zero trust and assume breach.
If a single edge device is compromised, that really shouldn't, ideally should not result in the compromise of your entire network,
doesn't have to result in a data breach.
You know, those core concepts or something that I think we have to get back to sort of
brilliance and the basics to deal with this kind of problem.
We'll be right back.
The research notes that many of these compromised devices are located in the United States.
Michael, what's the significance of that in terms of making them easy or difficult to detect
or block?
Yeah, I mean, it definitely makes it, you know, like the geographical location of a lot of the
bots in a lot of the botanets to be tracked not just JDI. It's rarely by chance a lot of
times we will see that there will be larger numbers of nodes in regions that
China has a strategic interest in targeting. You know we've seen that in previous
bot nets like Raptor Train. Raptor Train was a good example where we saw a more
even-heeled distribution of US and Taiwan-based bots or nodes that were a part of
that bot net and that was in direct alignment with the type of targeting we observed against
US and Taekwini's entities out of that network. The same applies here with with JDI.
So, you know, we obviously have a higher frequency of U.S.-based bots and it's, you know,
very likely not a not a coincidence that we're seeing that align almost directly with the type
of U.S.-based targeting that we see for this, this purving and scanning activity.
Definitely. And, you know, to add to Mike's point,
One implication of that is it makes traditional IP-based defenses like geo-fencing a little bit less effective.
So some of your listeners might have controls that you might block connections from IPs in countries like China or Russia.
But in this case, a lot of the IP addresses are in the United States.
And so they're not coming from China or Russia.
They look like they're coming from a residential IP space in Ohio or a mom-and-pop law firm.
in Texas. So it helps the threat actors blend into traditional or legitimate user traffic. It really
highlights the need to move beyond those kind of traditional IP-based defenses and you need to start
incorporating better cyber threat intelligence and sort of more behavioral controls. Can we dig into that
for just a second? I mean, what makes malicious reconnaissance from a home router look so much like
legitimate traffic. Help me understand that strategy.
So one strategy that is pretty common in enterprise environments, you might block connections
from known VPN providers or known data center IP addresses. You know, you can distinguish
pretty easily with IP enrichment between residential IP space and data center IP space.
And I know that if a data center is scanning me, it's a little bit more suspicious.
because that's likely someone that has set up some sort of automated.
They could be trying to brute force your VPN or scan your website.
It's just, it sticks out a little bit more for the defenders.
But when you have activity coming from residential IP space,
it just makes it a little bit harder to filter out and to block.
I'm curious from a technical point of view,
was there anything outstanding or interesting in your analysis here,
anything that set this apart from things you'd seen before.
Purely from like a capabilities standpoint for what JDI was able to do,
you know, it had some pretty intense like multi-protigal.
It was able to do banner grabs and service grabs and then also fingerprint those.
So it had follow-on filters that it was able to apply.
So it was able to kind of ignore, you know, generic filters or generic banner responses
that it would receive, which is basically just a, it's a, it's a,
way of saying that they were able to do like a fingerprinting plus on top of like a service that
they're able to provide back to whoever is consuming their scan results on the back end.
As part of their TLS certificate collection that they were doing, they were able to,
consumers of this data would be able to identify domain names or specific targets, specific
domains attached to those TLS certificates.
And then you also had the vulnerability driven programming that Ian already talked about,
which is, you know, this network was pivoting so quickly on recent vulnerabilities as they're announced.
So, again, from like a consumer standpoint of someone who would be looking through this data,
they're getting, you know, near real time, within hours of vulnerabilities being released,
very specific, attributed, and detailed results on, you know, on, let's use the Fortinet
vulnerability, for example, on all the Fortnite devices in very high-profile sector.
in the U.S., potentially within maybe three to six hours after vulnerability was released.
And that type of turnaround time, that speed, is probably one of the more concerning aspects
of something like JDI.
You know, so speed and scale, we talked about the scale as well, but speed in particular,
that turnaround time, but then scale on the fact that they're able to do this near surreptitiously
because of the spread across thousands of software devices, they're able to feedback this
data wanted to do without being noticed.
Yeah, one of the things that caught my eye was you all highlighted the adaptability of the
malware, that depending on the level of access that it had on a particular compromise device,
it would behave differently.
That struck me as being an interesting design choice.
Can you explain that to us?
So one interesting aspect of this malware is that if it had...
route or admin privileges on the target device,
then it was able to open up a raw socket, TCP socket,
and create a custom TCP packet
to allow the malware to launch SIN scans against its targets.
And those SIN scans basically allow really rapid scanning,
and it also prevents application level logging
on the target end.
If it did not have root privileges
or if it was conducting a web scan,
then it would just use the normal TCP stack
to basically enumerate the services that Mike talked about.
So grab things like TLS certificates
and service banners and things like that.
Mike, anything else that caught your eye?
I mean, I guess just to add on
to what you just said.
I mean,
the,
another,
another thing that,
uh,
that benefits for the threat actors is the overall noise reduction in
bandwidth limitations of,
or bypassing bandwidth limitations on home routers.
It's,
you know,
obviously that's a something we talked about where,
you know,
would a home user notice if their bandwidth spike because their home
router is scanning,
essentially scanning thousands or tens of thousands of,
um,
servers out on the internet.
Uh,
and perhaps if they were doing full TSP handshakes.
and hitting tens of thousands of nodes,
but when they're doing pure sin scanning,
like Gaines described,
where they could do it through the raw socket,
that, again, just allows them to do it more scalably,
but also remain extremely stealthy.
Looking at the big picture here,
what is your sense?
I mean, is this the shape of things to come
where adversaries maintain these standing reconnaissance platforms
so that they're always ready
when the next vulnerability is announced?
Yeah.
Definitely.
I think, you know, reconnaissance is becoming industrialized at scale, kind of like we talked about earlier.
You know, I think defenders, sometimes we tend to neglect reconnaissance.
You know, you often don't really hear about it.
And, you know, reading a threat intelligence report or an incident response report, you might not see very much on the recon side.
But there's a reason why it's the first step in the cyber kill chain.
You can't exploit a vulnerable device or service.
If you don't know, it exists.
And I think a lot of offensive security professionals, red teamers and pen testers,
would probably agree that reconnaissance is one of, if not the most important step in the process.
And so there's a sort of asymmetry there.
It's really important for attackers, but kind of neglected by defenders.
And this research shows that it's becoming a sort of foundation.
part of, oh, it was already a part of a foundational part of sort of nation, state level
activity, but it's only becoming more so. And it's, again, becoming industrialized. It's
happening at scale. It's happening faster and faster than ever before. So this is something
that we might need to start paying a little bit more attention to. Michael, any additional
thoughts on that? Yeah, I mean, I think we are definitely seeing industrialization and commercialization
of network infrastructure across the board.
I would say, I mean, we talk a lot about botnets,
obfuscation networks.
We've put out several blog posts on a few of those
and discussed orb networks,
proxy networks.
You know, all of those are, not all of them,
but a good portion of them are servicing multiple,
malicious threat actors that are operating over them
to enable their operations.
And so you have JDI involved in that first step
of the cyber kill chain, reconnaissance.
You've also got, you know,
There's weaponization and delivery after that, and that starts leading into exploitation.
And we're seeing that, you know, just across the board, for almost every step of the cyber kill chain at this point,
we're seeing different aspects of it being industrialized through shared orb networks, commercialization,
through shared scanning and probing results, fingerprinting databases.
You know, we're also seeing a lot of shared malware across threat actors.
It kind of used to be that threat actors would maintain a tight hold on,
on a lot of the custom malware and you start seeing that more and more with the shared malware,
or even just, you know, off-the-shelf tools that they can get freely available on GitHub
that are being shared across the board. So there's absolutely a just a full industrialization
of a large portion of the cycle chain at this point we're observing.
For the security folks in our audience, the people who are tasked with defending their own
organizations. Based on the research you all have put together here, what are your recommendations?
I think there are kind of two categories of recommendations. First, for listeners at home or if you're
in a small business, you want to make sure that your router doesn't end up compromised and a part
of this botnet. So basic cyber hygiene is important. You want to make sure that you're not using
old end-of-life routers or IoT devices and make sure that they're updated and that you apply
patches regularly and occasionally reboot those devices. And the second category is, you know,
for the larger organizations who might actually be targeted by the reconnaissance activity itself,
I think the two main recommendations, the priorities are really to, one, reduce your
external attack service, anything exposed to the internet as much as possible. And then two,
you're going to have to establish a vulnerability program that prioritizes patching, especially
for internet-facing devices.
There are more recommendations in the SISA and UK government reports that we link to in our blog.
A lot of them come down to kind of the foundational security controls that are often easier
said than done.
Things like hardening attack surface and securing credentials.
Again, the sort of foundational zero-trust type policies that we need to get better at to deal
with some of these actors like Bull Typhoon
who are using living off the land techniques
and leveraging these kinds of covert devices.
Our thanks to Ian Golden and Mike Horka
of Lumen's Black Lotus Labs,
we'll have a link to their research
entitled Expanded JDIYIOTE and Soho Botnet
enables rapid vulnerability exploitation in the show notes.
And that's Research Saturday,
brought to you by N2K Cyberwire.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights
that keep you a step ahead
in the rapidly changing world of cybersecurity.
If you like our show,
please share a rating and review
in your favorite podcast app.
Please also fill out the survey in the show notes
or send an email to Cyberwire
at n2K.com.
This episode was produced by Liz Stokes.
We're mixed by Elliot Peltzman and Trey Hester.
Our executive producer is Jennifer Ibin.
Peter Kilpie is our publisher,
and I'm Dave Bittner.
Thanks for listening.
We'll see you back here next time.
