Executive Summary
In June 2026, cybersecurity researchers reported a significant expansion of the JDY botnet, a covert network linked to Chinese state-sponsored actors. The botnet has grown from 650 to over 1,500 compromised small office and home office (SOHO) routers and IoT devices. This network is utilized for large-scale reconnaissance, enabling rapid identification and mapping of exposed services within hours of new vulnerability disclosures. The JDY botnet's resilience and adaptability underscore the persistent threat posed by state-sponsored cyber activities targeting critical infrastructure. The rapid expansion of the JDY botnet highlights the increasing sophistication of state-sponsored cyber operations. Organizations must prioritize timely patching of edge devices, enforce strong authentication measures, and monitor for indicators of compromise to mitigate the risks associated with such covert networks.
Why This Matters Now
The rapid expansion of the JDY botnet underscores the urgent need for organizations to enhance their cybersecurity defenses. With state-sponsored actors leveraging compromised devices for large-scale reconnaissance, timely patching and robust security measures are critical to prevent potential breaches and data exfiltration.
Attack Path Analysis
Chinese state-sponsored actors initiated the JDY botnet by exploiting vulnerabilities in SOHO routers and IoT devices, compromising over 1,500 devices. They escalated privileges within these devices to establish persistent control. The compromised devices were then used to scan and map exposed services, facilitating lateral movement within targeted networks. Command and control were maintained through a layered architecture using Tor nodes to manage infected infrastructure. The botnet conducted targeted reconnaissance and system profiling, exfiltrating structured data to central servers. The impact included evading traditional IP-based defenses and enabling further exploitation by Chinese threat actors.
Kill Chain Progression
Initial Compromise
Description
Exploited vulnerabilities in SOHO routers and IoT devices to compromise over 1,500 devices.
Related CVEs
CVE-2026-35616
CVSS 9.8A remote code execution vulnerability in Araknis Networks routers allows unauthenticated attackers to execute arbitrary code via crafted HTTP requests.
Affected Products:
Araknis Networks Araknis Routers – < 1.2.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Acquire Infrastructure: Botnet
Compromise Infrastructure: Botnet
Application Layer Protocol: Web Protocols
Ingress Tool Transfer
Command and Scripting Interpreter: Windows Command Shell
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Governance
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical infrastructure faces heightened reconnaissance risks from China-linked JDY botnet targeting SOHO/IoT devices, requiring enhanced east-west traffic security and encrypted communications.
Financial Services
Banking systems vulnerable to cyber reconnaissance campaigns exploiting unencrypted traffic and lateral movement, demanding zero trust segmentation and egress security controls.
Government Administration
Government networks at high risk from state-sponsored reconnaissance operations targeting 1,500+ devices, necessitating multicloud visibility and threat detection capabilities.
Health Care / Life Sciences
Healthcare infrastructure exposed to botnet scanning activities compromising HIPAA compliance, requiring encrypted traffic protection and anomaly detection for patient data security.
Sources
- China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissancehttps://thehackernews.com/2026/06/china-linked-jdy-botnet-expands-to-1500.htmlVerified
- Court-Authorized Operation Disrupts Worldwide Botnet Used by People’s Republic of China State-Sponsored Hackershttps://www.justice.gov/opa/pr/court-authorized-operation-disrupts-worldwide-botnet-used-peoples-republic-china-stateVerified
- NSA and Allies Issue Advisory about PRC-Linked Actors and Botnet Operationshttps://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3909590/nsa-and-allies-issue-advisory-about-prc-linked-actors-and-botnet-operations/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF primarily secures cloud workloads, its principles could inform strategies to limit the reach of compromised devices within the network.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls based on identity and context.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely restrict lateral movement by monitoring and controlling internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely provide insights into anomalous traffic patterns, potentially identifying and disrupting command and control channels.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic.
Implementing Aviatrix Zero Trust CNSF would likely reduce the overall impact by limiting the attacker's ability to exploit network vulnerabilities and move laterally.
Impact at a Glance
Affected Business Functions
- Network Security Monitoring
- Incident Response
- IT Infrastructure Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive network configurations and access credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement East-West Traffic Security to monitor and control lateral movement within networks.
- • Deploy Zero Trust Segmentation to enforce least privilege access and limit the spread of compromises.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.



