Black Lotus Labs hero image

Expanded JDY IoT and SOHO botnet enables rapid vulnerability exploitation

Black Lotus Labs tracks the JDY botnet as it spreads through IoT devices and SOHO routers worldwide. It grew from about 1,100 devices on August 16, 2023 to around 9,000 by September 9, driven by exploits for CVE-2023-28771 and CVE-2023-1389. Most infections hit Teltonika RUT9XX routers, and 64% of one identified cluster was in Moldova. The campaign overlaps with sp1r1t infrastructure. Defenders should patch exposed edge devices fast, limit access, and watch for unusual shell commands or download activity.

  • Black Lotus Labs identified JDY as a fast-growing botnet infecting IoT devices and SOHO routers worldwide.
  • The JDY botnet rapidly expanded by weaponizing newly disclosed vulnerabilities affecting several internet-exposed edge device types.
  • Black Lotus Labs found overlap between JDY infrastructure and the earlier sp1r1t DDoS malware campaign.
  • Organizations should patch exposed edge devices quickly and restrict vulnerable services to reduce compromise risk.
  • The JDY botnet shows how quickly threat actors can scale attacks against poorly secured embedded networking equipment.
Published on Jun 10, 2026 | 11 minute read