Security experts sound alarm over expanded China-linked botnet used to target US critical infrastructure and military assets
Summary
Security researchers warn that the JDY botnet has expanded to about 1,500 compromised devices and is being used to scan for exposed services on routers, cameras, and other edge systems. The campaign now spans multiple manufacturers and relies heavily on vulnerable SOHO and IoT devices, with most infected devices located in the US. The report highlights selective scanning of newly disclosed vulnerabilities, including Fortinet equipment, which shows the operators are actively hunting for easy exploitation opportunities. Enterprises are advised to patch edge devices quickly, keep security updates current, and consider SASE or similar controls to reduce exposure. The article also argues that traditional IP-based defenses such as geofencing and static blocklists are increasingly ineffective against this kind of botnet activity.