JDY Botnet's Quiet Comeback: 1,500 SOHO and IoT Nodes Now Mapping the Internet
Researchers tie the reconstituted scanner network to China-nexus operators conducting persistent, large-scale reconnaissance against exposed services.

A covert scanning network attributed to China-nexus state actors is back, and it is bigger than the version researchers tracked last year.
The so-called JDY botnet now comprises more than 1,500 small-office, home-office and IoT devices, according to telemetry from Lumen's Black Lotus Labs. The operators are not running ransomware. They are not stealing crypto. They are mapping.
That distinction matters for defenders, and it matters for regulators who have spent the last two years tightening reporting obligations around state-linked intrusion activity.
Black Lotus Labs describes JDY as a "centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale." In plain terms: the botnet is reconnaissance infrastructure. Its job is to feed a target list to whoever sits upstream.
The resurgence follows a pattern U.S. and allied agencies have flagged repeatedly in advisories on Volt Typhoon and adjacent clusters — China-nexus crews routing operations through compromised edge devices to blunt attribution and frustrate network defenders. Routers, IP cameras and aging SOHO gear remain the preferred substrate. Patch cycles are long. Logging is thin. Owners rarely notice.
The policy backdrop is not subtle.
CISA's Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) proposed rule, published at 89 Fed. Reg. 23644 on April 4, 2024, would require covered entities to report substantial cyber incidents within 72 hours. The comment period closed July 3, 2024, and the final rule has not yet been issued. Reconnaissance scanning, on its own, generally would not trip the reporting threshold under the proposed §226.1 definitions. Follow-on intrusions enabled by that scanning almost certainly would.
Publicly traded victims face a parallel obligation. The SEC's final cybersecurity disclosure rule, adopted in Release No. 33-11216, requires Item 1.05 Form 8-K filings within four business days of determining an incident is material. The Commission has been explicit that the clock runs from materiality determination, not initial detection — a distinction that becomes awkward when an intrusion begins with months of quiet fingerprinting by infrastructure like JDY.
On the sanctions front, OFAC and Treasury have continued to designate individuals and front companies tied to PRC contract hacking, including the March 2024 action against Wuhan Xiaoruizhi Science and Technology Co. Owners of compromised SOHO devices are not themselves sanctions targets. Service providers knowingly facilitating designated actors are.
Defenders with edge fleets should assume scanning traffic from residential and small-business IP space is not benign background noise. Network operators seeing repeated, structured fingerprinting from rotating SOHO ranges should preserve logs. If an intrusion follows, those logs will determine both the CIRCIA narrative and, for public companies, the materiality memo.
The rulebook is being written around exactly this kind of activity. The botnet is not waiting for the comment period to close.



