Security1 distinct publisher3 min readPublished
Black Lotus Labs counted about 650 JDY bots at the January 2024 low and more than 1,500 now, all of them fingerprinting exposed services soon after CVEs go public, with US military entities the most prominent target.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The 2024 action landed on the half of the operation that touched victims. Inside KV-botnet there were four clusters, the KV cluster running as a covert data transfer network and the JDY cluster doing scanning and reconnaissance [5]. Public disclosure plus US government takedown effort from late 2023 into early 2024 left KV largely defunct [6]. JDY stayed up [7]. The cluster that survived is the one whose entire function is sending packets at strangers' open ports, which is also the cheapest function in the set to rebuild.
The arithmetic shows how cheap. Black Lotus Labs put the January 2024 floor at roughly 650 bots talking to JDY command and control [8], and the current figure at more than 1,500 [2], which the researchers characterise as more than doubling since the takedown [14]. Subtract: at least 850 devices added [1]. Divide: a multiple of about 2.3 [2]. A router recruited to scan has to do less work, and survive less scrutiny, than a router carrying espionage traffic for an operator who needs it to stay quiet for months.
Separate what is measured from what is inferred. Lumen states the scanning shows a clear focus on identifying vulnerable infrastructure shortly after public vulnerability disclosures, and says this suggests reconnaissance output is rapidly operationalised by China-nexus APT actors [9]. Suggests is the researchers' word, and the published summary characterises the timing only in those terms, with no measured interval between a disclosure and the corresponding scan [13]. So the exposure window here is a scan cycle on infrastructure that is already standing and already funded, not a campaign someone has to spin up. Anyone converting that into a number of hours is filling in a blank the research left open.
The targeting is the part with a name attached. Activity spans a range of sectors, with US military and associated entities the most prominent [10]. For an organisation in that orbit, the useful assumption is that the fingerprint of its perimeter already exists in someone's triage queue, because JDY discovers, fingerprints and continuously maps exposed services and feeds the structured output into a larger scanning ecosystem for target identification [3]. Nothing in that chain requires a compromised device on your own network.
Which sets the cost boundary. You cannot patch another company's home router, and Black Lotus Labs frames the countermeasure as UK NCSC guidance on defending against China-nexus covert networks of compromised devices [11]. Two variables stay local: the edge inventory that gets recruited, and the gap between a disclosure and your own patch. Lumen has been tracking this category since Raptor Train and describes purpose-built reconnaissance infrastructure as a durable component of nation-state operations rather than an incident [12]. Takedowns have now demonstrated they can kill the transfer layer and leave the targeting layer counting your ports.
Ranked by verification strength, evidence, and original report placement.
Black Lotus Labs identified a resurgence and expansion of the JDY botnet, a covert network linked to Chinese nation-state-backed actors, including Volt Typhoon.
The JDY botnet comprises more than 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices actively conducting targeted scanning and service fingerprinting.
JDY operates as a centrally controlled, high-performance scanner used to discover, fingerprint and continuously map exposed services at scale, feeding structured reconnaissance data into a larger scanning ecosystem for triage, target identification and exploitation.
The targeted focus has been observed across a range of sectors, with the US military and associated entities as the most prominent.
In December 2023 Black Lotus Labs disclosed KV-botnet, a covert network of thousands of SOHO routers and firewall devices used by China-based APTs, most notably Volt Typhoon, for espionage and intelligence operations targeting US critical infrastructure.
KV-botnet consisted of four clusters; the KV cluster was used as a covert data transfer network and the JDY cluster was used for scanning and reconnaissance.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
One infrastructure broker sells stealth to multiple Chinese espionage crews at once1 distinct publisher
security
One packet reboots your Cisco VPN box, and Cisco will not say who is firing it1 distinct publisher
security
A cracked spreadsheet, a dead man's passwords, and the control nobody documents1 distinct publisher
product
DOJ names China's proxy quartermaster; the seizure took domains, not devices1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-hand telemetry, single hand
The strength here is provenance: Lumen is watching JDY's command-and-control traffic itself, and bot counts, geography and device makes are the kind of thing that sensor position lets you say. The weakness is that no one else has looked. The Volt Typhoon attribution is inherited from the team's own 2023 KV-botnet work, the sector ranking arrives without a named victim, and the published text breaks off mid-sentence exactly where the scan results are being described.
Real scale, one sensor network
Read as deployment in the wild, the botnet's footprint is concrete and growing: 1,500-plus live devices, a manufacturer spread that has expanded well past the original pair of Cisco routers, and a US-heavy distribution that is operationally consequential. What holds the number down is that the entire count rests on what one provider's visibility can see, with no independent scan data, ISP notification figures or takedown status to triangulate against.
Exploitation in the title, scanning in the data
The headline promise is rapid vulnerability exploitation; what is actually shown is fingerprinting. Between those two sits an inference — that reconnaissance output is handed to APT operators and used quickly — which Lumen makes without a single named vulnerability or a measured hours-to-scan figure. The device counts are, if anything, the modest part of the piece; the framing runs ahead of them.
House research from an interested party
Black Lotus Labs is Lumen's research arm, and Lumen sells network and managed security services to precisely the enterprises being told their scanning defences no longer work. That does not make the telemetry wrong — vendor visibility is how most botnets get found — but the sole account of this threat is published by a company that benefits from the threat being taken seriously, and it never says so. The recommendation pointing to NCSC guidance rather than a Lumen product cuts slightly against the pattern.
Plausible, unreplicated
Hold this one loosely. The mechanics are coherent and consistent with well-documented tradecraft, and the arithmetic checks out, so the core finding — a scanning botnet outlived the takedown and grew — is likely sound. But a single unreplicated post, a truncated body, and an attribution and targeting picture that no third party has confirmed leave little room to be firmer than even odds on the specifics.