Research Saturday 8.15.26
Ep 437 | 8.15.26

The botnet that scouts before it strikes.

Transcript

Dave Bittner: Hello everyone and welcome to the Cyberwire's Research Saturday. I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems, and protecting ourselves in a rapidly evolving cyberspace. Thanks for joining us. [ Music ]

Ian Goldin: And actually recently we observed a resurgence of this JDY Botnet, and it's expanded in a couple of different ways, and that's really what prompted us to start digging into it again and, you know, put out the research that is the subject of this blog.

Dave Bittner: That's Ian Goldin, Senior Lead Information Security Engineer, along with Mike Horka, Principal Information Security Engineer, from Lumen's Black Lotus Labs. They'll both be discussing their research entitled "Expanded JDY IOT, and SOHO Botnet Enables Rapid Vulnerability Exploitation." [ Music ]

Mike Horka: So this story goes back a couple of years. It involves Chinese APTs and cyber espionage, so it's actually not a new network. A few years ago, we published some research on another network called the KV Botnet, and the KV Botnet was important because it was linked to Volt Typhoon, which is of course the infamous Chinese APT responsible for targeting critical infrastructure providers, and at the time, the KV Botnet was used as a covert network, and you'll hear this term sometimes also referred to as an ORB Network, or Operational Relay Box Network, but they're basically groups of devices, sometimes compromised devices that adversaries use to relay and proxy their traffic to obfuscate who they are, where they're coming from, and basically it helps them blend in with normal traffic, and so when we were doing our research on the KV Botnet, we noticed it had kind of two main clusters, there is the KV side, which was sort of a covert data transfer network, and then the other side was, we called it the JDY Cluster, and it was used for reconnaissance and targeting. The KV side of the network was disrupted by a law enforcement take-down a couple years ago and has been pretty defunct since then, but the DJY side, the reconnaissance part, has never gone away and actually recently we observed a resurgence of this JDY Botnet, and it has expanded in a couple of different ways, and that is really what prompted us to start digging into it again, and you know, put out the research that is the subject of this blog.

Dave Bittner: Michael, I'm curious, when did you all realize that this wasn't just a botnet that had survived those earlier takedowns, but one that had actually grown into something a bit more capable?

Mike Horka: You know, initially it was definitely size, the botnet, or the JDY Cluster that we were tracking during the days of KV Botnet was more-- I would call it more small-scale. I think the peak that we would see was maybe 750, 800 bots or infected nodes, that were tracking into that cluster, but more recently that had at least doubled, and we were seeing an increase in scanning activity and probing activity coming out of that cluster.

Dave Bittner: You know, one of the things that struck me when I was going through the research was how much diversity there is in the compromised devices. Why would the threat actor expand beyond just a few router models to all these different SOHO and IoT devices? Ian?

Ian Goldin: Yeah, I think the short answer is that it makes it harder to track and block these devices. So like you said, you know, initially years ago it was basically two Cisco router models that they were using and more recently you know, it's essentially doubled in size. There are now more than 1,500 compromised bots that are a part of this network, and in addition to the increase in size, we're also seeing a diversification of device types, like you mentioned, so we're seeing other vendors being exploited, like Ubiquity, Hikvision, Linksys, you know, kind of the typical SOHO and IoT device types that you often see in botnets, and you know, the reason, the advantage that gives the threat actors is essentially, you know, it's scale plus diversity, again, it makes it harder to detect and block. It gives them more options. It helps them blend in with different kinds of traffic, and it makes it harder to take down, you know, if there is another law enforcement takedown effort, it just gives them more places to hide.

Dave Bittner: Michael, the research describes JDY primarily as a reconnaissance platform rather than an exploitation platform. Can you help us understand the difference there, and why reconnaissance is valuable for an advanced threat actor?

Mike Horka: Yeah, absolutely, yeah so we do-we track JDY, more generally as a scalable reconnaissance botnet. Its primary purpose is not pure exploitation or data theft or launching dinos attacks, that's very commonly understood for the botnet terminology. Instead JDY's primary purpose was to identify exposed services, fingerprint devices and servers, and then rapidly locate vulnerability structure. So this particular type of telemetry they were to gather, is, we would assess, fed back into the back-end, like intelligence collection database, where then multiple China-nexus threat actors can parse creating-and filter through this data-to guide or follow malicious activity. So how is that useful? You can kind of think about, you know, JDY as being like the initial scout. And its job isn't necessarily to attack the target, but its job is to identify locked doors, open windows, and fingerprint them in a way to provide enough information when they come back to report back into this database, so then you've got a follow in malicious threat actors who could take that information and action it in some way.

Dave Bittner: Well, if I owned one of these infected routers, what would it be spending its time doing? And would I even notice?

Mike Horka: In a distributed fashion, perhaps not. You know? And that's-and that's part of the benefit to, you know, to the operators of this botnet, in expanding to 1,500 and more compromised devices is that you are spreading out that load across all of those devices, so as a home user with a home router that may be compromised, you know, maybe initially when you're one of-when you're one of 50 or 100 bots in the net, in the network, you may notice a spike in your bandwidth, you know? Or an unresponsive home router on a regular basis, but when you've got this distributed across thousands of nodes, it's far less likely that you're even going to notice as a home user.

Dave Bittner: You know, the research talks about how the malware doesn't just scan everything indiscriminately. It's pretty selective in what it's doing. Ian, what's the significance of that?

Ian Goldin: Yeah, that's really important. There is definitely intentional targeting. But it's also-it's scale, so you know, some of these nodes are scanning hundreds of thousands of target IP addresses at a time. But it's not indiscriminate. It's not scanning the entire internet. It's not a replacement for something like Censys or Shodan, you know, these websites that basically scan and index the internet. There is a pretty strong focus on organizations that seem to align with Chinese geopolitical interests, so for example, organizations that are related to the military. And that kind of reinforces the idea that this is part of a broader intelligence collection and exploitation pipeline, and the point that Mike made earlier about the difference between reconnaissance and exploitation is really critical. You know, we think this is all-this is one piece of the puzzle, and so one of the really interesting things we saw was, so back in April, there was a new Fordenent vulnerability that was disclosed, I think it was the CVSS score of 9.8, so a critical vulnerability. And basically within hours of the disclosure of that CVE, we saw a significant spike of scanning from the JDY bots against Fordenent devices. So clearly a threat actor is monitoring for new vulnerabilities since they're released, and then essentially tasking this botnet to go out and look for vulnerable devices that might be, you know, vulnerable to that CVE, so it's not random or indiscriminate. It's targeted in you know a couple of different key ways. And again, that speaks to the fact or our assessment that this is one part of kind of this larger exploitation pipeline.

Dave Bittner: Does this suggest that reconnaissance has become kind of an industrialized process, where, you know, these vulnerabilities get identified and maybe queued up for follow on operations really quickly? You know, I mean, the research really highlights the speed of exploitation here.

Ian Goldin: Absolutely. I think one of the key takeaways for defenders, you know, reconnaissance is happening continuously. And exploitation is happening continuously, and they're happening at scale, and you know, of course, now with AI, they're happening faster than ever before, and that's really the difference that we're dealing with today. You know, it has the potential to give adversaries the upper hand. And so, you know, defenders are just going to be-have to be faster. They're going to be-have to be faster at prioritizing and patching new vulnerabilities, especially for internet-facing devices, and when intrusions do happen, you know, they're going to have to be faster at detecting them and responding to them. This is why we have concepts like zero trust, and assume breach, you know? If a single edge device is compromised that really shouldn't-ideally should not result in the compromise of your entire network. Doesn't have to result in a data breach, you know, there's core concepts or something that I think we have to get back to sort of brilliance in the basics, to deal with this kind of problem. [ Music ]

Dave Bittner: We'll be right back. [ Music ] The research notes that many of these compromised devices are located in the United States. Michael, what's the significance of that, in terms of making them easy or difficult to detect or block?

Mike Horka: Yeah, I mean, it definitely makes it, you know, like the geographical location of a lot of the bots-in a lot of the botnets-will be tracked not just JDY. It's rarely by chance. A lot of times, we will see that there will be larger numbers of nodes in regions that China has a strategic interest in targeting. You know, we've seen that in previous botnets like Raptor Train. Raptor Train was a good example where we saw a more even-keeled distribution of U.S. and Taiwan-based bots or nodes that were part of that botnet, and that was indirect alignment with the type of targeting we observed against U.S. and Taiwanese entities out of that network. The same applies here with JDY. So you know, we obviously have a higher frequency of U.S. based bots, and it's, you know, very likely not a coincidence that we're seeing that align almost directly with a type of U.S.-based targeting that we see for this probing and scanning activity.

Ian Goldin: Definitely, and you know, to add to Mike's point, one implication of that is it makes traditional IP-based defenses like Geofencing a little bit less effective, so you see, some of your listeners might have-might have controls that, you know, you might block connections from IPs in countries like China or Russia, but in this case, a lot of the IP addresses are in the United States and so they're not coming from China or Russia, they look like they're coming from residential IP space in Ohio, or a mom and pop law firm in Texas. So it helps the threat actors blend into traditional or legitimate user traffic. It really highlights the need to move beyond those kind of traditional IP-based defenses, and you need to start incorporating, you know, better cyber threat intelligence, and sort of more behavioral controls.

Dave Bittner: Can we dig into that for just a second? I mean, what makes malicious reconnaissance from a home router look so much like legitimate traffic? Help me understand that strategy?

Mike Horka: So one strategy that is pretty common in enterprise environments is you might block connections from known VPN providers, or known data center IP addresses, you know, you can distinguish pretty easily with IP enrichment between residential IP space, and data center IP space. And I know that if a data center is scanning me, it's a little bit more suspicious, because you know, that's likely someone that has set up some sort of automated, you know, they could be trying to brute-force your VPN, or scan your website. It just-it sticks out a little bit more for the defenders. But when you have activity coming from residential IP space, it just makes it a little bit harder to filter out and to block.

Dave Bittner: I'm curious from a technical point of view, was there anything outstanding or interesting in your analysis here? Anything that set this apart from things you'd seen before?

Mike Horka: Purely for like a capabilities standpoint for what JDY was able to do, you know, it had some pretty intense like multi-protocol. It was able to do beta grabs, and service grabs, and then also fingerprint those, so it had a follow on filters it was able to apply. So it was able to kind of ignore, you know, generic filters or generic beta responses it would receive. Which is basically just-it's a way of saying that they were able to do like a fingerprinting plus on top of like a service that they were able to provide back to whoever is consuming their scan results on the back end, as part of their TOS certificate collection that they were doing, they were able to-consumers of this data-would be able to identify domain names, or specific targets. Specific domains attached to those TOS certificates. And then you also had the vulnerability driven program that Ian already talked about, which is, you know, this network was pivoting so quickly on recent vulnerabilities as they're announced, so again, from like a consumer standpoint of someone who would be looking through this data, they're getting, you know, near-real-time, within hours of vulnerabilities being released, very specific attributed and detailed results on, you know, on let's use the Fordenent vulnerability for example. On all the Fordenent devices in very high profile sectors in the U.S., you know, potentially within maybe three to six hours after a vulnerability is released, and that type of turnaround time, that speed, it's probably one of the more concerning aspects of-on something like JDY. And, so speed and scale, we talked about the scale as well, but speed in particular, that turnaround time, but scale on the fact that they were able to do this near-surreptitiously because of the spread across thousands of-several devices, they were able to feedback this data, largely without being noticed.

Dave Bittner: Yeah, one of the things that caught my eye was you know, how highlighted the adaptability of the malware, that depending on the level of access that it had on a particular compromised device, it would behave differently. Now that struck me as being an interesting design choice. Can you explain that to us?

Ian Goldin: So one interesting aspect of this malware is that if it had root or admin privileges on the target device, then it was able to open up a raw socket, TCP socket, and create a custom TCP packet to allow the malware to launch sim scans against its targets, and those sim scans basically allow really rapid scanning and it also prevents application-level logging on the target end. So if it did not have root privileges, or if it was conducting a web scan, then it would just use normal-it would use the normal TCP stack to basically enumerate the services that Mike talked about, so grab things like TLS Certificates and service banners, and things like that.

Dave Bittner: Mike, anything else that caught your eye?

Mike Horka: I mean, I guess just to add on to what Ian just said, I mean, the-another thing that that benefits for the front actors is the overall noise reduction and bandwidth limitations of, or bypassing bandwidth limitations on home routers. It's, you know, obviously it's something we talked about where, you know, would a home user notice if their bandwidth spiked because their home router is scanning-potentially scanning-thousands or tens of thousands of servers out on the internet, and perhaps if they were doing full TCP handshakes, you know, and hitting tens of thousands of nodes, but when they're doing pure sim scanning, like Ian just described where they could do it through the raw socket, that again just allows them to do it more scalable, but also remain extremely stealthy.

Dave Bittner: Looking at the big picture here, what is your sense? I mean, is this the shape of things to come where adversaries maintain these standing reconnaissance platforms so that they're always ready when the next vulnerability is announced? Ian?

Ian Goldin: Definitely. I think, you know, reconnaissance is becoming industrialized at scale, kind of like we talked about earlier. You know, I think defenders sometimes we tend to neglect reconnaissance. You know, you often don't really hear about it, and if you're reading a threat intelligence report or an incident response report, you might not see very much on the recon side, but there's a reason why it's the first step in the cyber kill chain. You can't exploit a vulnerable device or service if you don't know it exists. And I think a lot of authentic security professionals, you know, red-teamers and pen testers, would probably agree that reconnaissance is one of if not the most important step in the process. And so there's a sort of asymmetry there. It's really important for attackers to kind of neglect it by defenders, and this research shows that, you know, it's becoming a sort of foundational part of or it was already a part of a foundational part of sort of nation-state level activity, but it's only becoming more so, and you know, it's again becoming industrialized. It's happening at scale. It's happening faster and faster than ever before. So this is something that we might need to start paying a little bit more attention to.

Dave Bittner: Michael, any additional thoughts on that?

Mike Horka: Yeah, I mean, I think we are definitely seeing industrialization and commercialization of network infrastructure across the board, I would say. I mean, we talk a lot about botnet, obfuscation networks, we've put out several blog posts on a few of those, and discussed board networks. Privacy networks. You know, all of those-not all of them, but a good portion of them-are servicing multiple malicious threat actors that are operating over them to enable their operations. And so you have JDY involved in that first step of the cyber kill chain. Reconnaissance. You've also got, there's weaponization and delivery after that, and that starts leading into exploitation. And we're seeing that, you know, just across the board for-for almost every step of the cyber kill chain at this point. We're seeing different aspects of it being industrialized through shared orb networks, virtualization through shared scanning and probing results, fingerprinting databases. You know, we're also seeing a lot of shared malware across threat actors. It kind of used to be that threat actors would maintain a tight hold on a lot of the custom malware, and you'd start seeing that more and more with the shared malware, or even just you know off the shelf tools that they can get freely available on GitHub that are being shared across the board. So there's absolutely a-just a full industrialization of a large portion of the cyber kill chain at this point, that we're observing.

Dave Bittner: For the security folks in our audience, the people who are tasked with defending their own organizations, based on the research you all have put together here, what are your recommendations?

Ian Goldin: I think there are kind of two categories of recommendations. You know, first for listeners at home, or if you're into small business, you want to make sure that your router doesn't end up compromised, and a part of this botnet, so basic cyber hygiene is important. You want to make sure you're not using old, end-of-life routers, or IoT devices, and make sure that they're updated, and that you apply patches regularly, and occasionally reboot those devices. And the second category is, you know, for the large organizations who might actually be targeted by the reconnaissance activity itself, I think the two main recommendations, the priorities are really to one, reduce your external attack surface, anything exposed to the internet, as much as possible, and then two, you're going to have to establish a vulnerability program that prioritizes patching, especially for internet-facing devices. There are more recommendations in the CISA and U.K. government reports that we linked to in our blog. A lot of them come down to kind of the foundational security controls that are often easier said than done, you know, things like hardening attack surface, and securing credentials. Again, this sort of foundational zero-trust type policies that we need to get better at to deal with some of these actors, like Volt Typhoon, who are using living off the land techniques, and leveraging these kinds of covert devices. [ Music ]

Dave Bittner: Our thanks to Ian Goldin and Mike Horka, of Lumen's Black Lotus Labs. We'll have a link to their research entitled Expanded JDY IoT, and SOHO Botnet Enables Rapid Vulnerability Exploitation in the show notes.

Dave Bittner: And that's Research Saturday, brought to you by N2K's Cyberwire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights to keep you a step ahead in the rapidly-changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes, or send an email to Cyberwire, at N2K.com. This episode was produced by Liz Stokes. We're mixed by Elliot Pelsman, and Trey Hester. Our Executive Producer is Jennifer Eiben. Peter Kilpe is our Publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here next time. [ Music ]