Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosGoogle Chrome: Unfinished Projects by Chrome: Joe Burrow’s Chess Set(21.09.2026 um 16:05 Uhr)
YouTube Security VideosGitHub: How to move AI from code completion to agentic workflows(21.09.2026 um 17:00 Uhr)
YouTube Security VideosGoogle Workspace: Why are we like this 😭 #Shorts(21.09.2026 um 16:15 Uhr)
Windows Tipps & SecurityNeues Elektroauto von Rolls-Royce wird äußerst exklusiv sein(21.09.2026 um 16:46 Uhr)
Windows Tipps & SecurityGooglebooks überraschen: Die beste KI-Funktion ist gar keine KI(21.09.2026 um 16:59 Uhr)
YouTube Security VideosGoogle Chrome: Unfinished Projects by Chrome: Joe Burrow’s Chess Set(21.09.2026 um 16:05 Uhr)
YouTube Security VideosGitHub: How to move AI from code completion to agentic workflows(21.09.2026 um 17:00 Uhr)
YouTube Security VideosGoogle Workspace: Why are we like this 😭 #Shorts(21.09.2026 um 16:15 Uhr)
Windows Tipps & SecurityNeues Elektroauto von Rolls-Royce wird äußerst exklusiv sein(21.09.2026 um 16:46 Uhr)
Windows Tipps & SecurityGooglebooks überraschen: Die beste KI-Funktion ist gar keine KI(21.09.2026 um 16:59 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

China-linked recon botnet outpaces enterprise defenses

A botnet made up of compromised small office and Internet of Things devices has grown into a larger reconnaissance network capable of rapidly identifying vulnerable internet-facing systems after public vulnerability disclosures,…

0
↗ Quelle (csoonline.com)
Reagiere als Erste:r — dein Feedback zählt!








A botnet made up of compromised small office and Internet of Things devices has grown into a larger reconnaissance network capable of rapidly identifying vulnerable internet-facing systems after public vulnerability disclosures, researchers said.





The botnet, tracked by Lumen’s Black Lotus Labs as JDY, now comprises more than 1,500 compromised small office and home office, or SOHO, and IoT devices, and is being used to “discover, fingerprint and continuously map exposed services at scale.”





Lumen said the activity is linked to Chinese nation-state-backed actors, including Volt Typhoon. The findings point to a growing challenge for enterprise security teams. Many enterprise edge systems remain outside traditional endpoint monitoring, giving adversaries room to move quickly from vulnerability disclosure to targeted reconnaissance.





Lumen added that JDY’s distributed infrastructure can also help operators evade geofencing and other IP-based defenses because the activity may appear to come from legitimate residential or small-business internet traffic.





JDY undermines several defensive assumptions that many enterprises still rely on, according to Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services. 





Geofencing and IP reputation controls have limited value when used in isolation, Grover said, while static blocklists are structurally weak against botnets that continuously rotate compromised infrastructure. JDY also exposes a broader visibility gap around edge devices, which are often difficult for enterprises to monitor with the same rigor as endpoints and cloud workloads.





Reconnaissance moves closer to attack





Analysts said that CISOs should not dismiss JDY as just another botnet.





“The reported JDY activity shows a clear focus on discovering, fingerprinting, and continuously mapping exposed services at scale, including shortly after public vulnerability disclosures,” Grover said. “That points to a more industrialized model of pre-exploitation reconnaissance, where compromised edge devices are used not merely for disruption or commodity abuse, but to generate timely targeting intelligence for follow-on operations.”





That means the compromised SOHO and IoT devices may not be the final target. Instead, they provide the scanning layer used to identify exposed enterprise infrastructure, including routers, firewalls, VPNs, cameras, and other internet-facing systems.





Devashri Datta, a cybersecurity researcher, said CISOs should treat JDY as evidence of a shift in how reconnaissance is being operationalized.





“If JDY is sitting in your risk register under ‘routine botnet management’, your defensive playbook will fail before it starts,” Datta said. “JDY isn’t designed to DDoS anyone, steal credentials, or mine cryptocurrency. It is a centrally controlled, high-performance scanning engine.”





Patch timelines come under pressure





The scanning activity also raises questions about whether conventional vulnerability management timelines are still workable for perimeter systems exposed to the internet.





“Traditional SLA-driven patching is no longer defensible for perimeter devices,” Datta said.





The size of the botnet matters less than the speed of its targeting cycle, according to Sanchit Vir Gogia, chief analyst at Greyhound Research. “Fifteen hundred devices that find the right vulnerable systems within hours are worth more than a hundred thousand generating noise,” Gogia said. “Exploitation no longer begins when malicious code arrives. It begins when exposure is discovered.”





The concern is that JDY may already have collected much of the information attackers need before a new vulnerability is disclosed. Datta said the botnet’s reconnaissance can include IP addresses, port configurations, protocol information, service banners, TLS versions, certificate metadata, and associated domains.





That gives operators a head start when a critical flaw becomes public. Lumen said Black Lotus Labs observed a selective increase in scans of Fortinet equipment shortly after the disclosure of CVE-2026-35616, indicating the ability and intent to identify vulnerable devices before patches are widely applied.





For CISOs, Datta said, the response requires pre-approved playbooks for perimeter devices, including accelerated patching, access control list changes, temporary disabling of exposed features, and lockdown of management interfaces.


Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten China-linked recon botnet outpaces enterprise defenses

Thematisch verwandte Begriffe: Chinalinked, recon, botnet, outpaces · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94393 | When a user creates or edits a report inside an event, MISP can identify…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick