ClosedMedium impactAI Refreshed

Chinese state-linked JDY botnet expands to 1,500 hacked routers conducting rapid vulnerability reconnaissance

Detected 15 Jun 2026Occurrence date not yet established -- showing first detection by the desk.·
Global cyber threat infrastructure spanning compromised routers worldwide2 reportsEnded 28 Jun 2026
CyberPropertyCyberCasualty & Liability

Lumen's Black Lotus Labs reports that the Chinese state-linked JDY botnet has expanded to roughly 1,500 compromised SOHO routers, primarily Linksys and Mimosa Networks devices, and is conducting vulnerability reconnaissance within hours of new CVE disclosures. Mainstream media coverage corroborates the scale and rapid weaponisation behaviour. No insured losses, breach notifications, or confirmed exploitation against insured entities have been reported; severity reflects capability and intent rather than realised loss.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. MEDIUM: A state-linked botnet of roughly 1,500 SOHO routers weaponising newly disclosed CVEs within hours signals a measurable systemic reconnaissance capability rather than a confirmed insured loss event. The absence of insured casualties, breach notifications, or specific exploited CVEs in insured populations prevents elevation to a market-moving cyber loss. The speed-of-weaponisation signal is actionable for cyber accumulation monitoring and war-risk cyber underwriting, but severity banding rests on capability and intent, not realised insured losses. No insured-industry loss figures are available to floor or cap severity.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Affected countries

🇨🇳 China

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts