ADVERTISEMENT

China-linked JDY botnet rapidly exploits new flaws, raising fresh Volt Typhoon concerns

A covert botnet linked to the Chinese nation-state actors Volt Typhoon – and first observed in 2024 – has more than doubled in size and is now actively targeting the US military and associated entities, new research finds.

Cisco China attack
Stefanie Schappert
Stefanie Schappert Senior Journalist
June 11, 2026 3 min read
Key takeaways:
JDY by country
The geographic distribution of the JDY botnet shows that most devices are located in the United States. Image by Black Lotus Labs

JDY moves fast on newly disclosed flaws

New Black Lotus Labs research links growing JDY botnet activity to China-nexus threat activity.

China-linked botnet gathers intelligence at scale

JDY top targeted devices
Scanning of Fortinet devices increased hours after disclosure of new Fortinet vulnerability CVE-2026-35616. Image by Black Lotus Labs

Routers help attackers hide in plain sight

Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.
ADVERTISEMENT
JDY expands device manufacturers targeted
Top 5 manufacturers of devices comprising the JDY botnet and the number of compromised devices. Image by Black Lotus Labs

From KV-botnet to Volt Typhoon concerns

Botnet
Researchers say JDY has grown to roughly 1,500 infected devices. Image by Shutterstock
China routers
Compromised routers have played a key role in Volt Typhoon operations. Image by Mehaniq | Shutterstock

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites

ADVERTISEMENT