logo
blogtopicsabout
logo
blogtopicsabout

Resurgent Chinese Botnet & AI Influence Ops Target US Infrastructure

AICybersecuritySecurityChinaBotnet
June 11, 2026

TL;DR

  • •A China-linked botnet, 'JDY,' has resurfaced with over 1,500 compromised devices.
  • •Chinese actors used OpenAI's ChatGPT to generate content aimed at influencing public opinion on AI datacenters.
  • •The activity highlights ongoing Chinese efforts to gather intelligence and conduct influence operations using advanced tech.

Recent reports indicate continued cyber activity originating from China, encompassing both the resurgence of a known botnet and attempts to influence public discourse surrounding AI infrastructure. This activity demonstrates a sophisticated and multi-faceted approach to exploiting vulnerabilities and shaping narratives.

What Happened

According to Lumen’s Black Lotus Labs, the JDY cluster of the KV-botnet – previously disrupted by the FBI in January 2024 – has seen a significant resurgence, now comprising over 1,500 compromised routers and IoT devices. This botnet is actively scanning for and exploiting recently disclosed vulnerabilities, with a particular focus on US military and associated entities. The report suggests a rapid operationalization of reconnaissance output by China-nexus Advanced Persistent Threat (APT) actors.

Separately, OpenAI reported banning ChatGPT accounts linked to China that were used to generate content for influence operations. These operations targeted the debate around AI datacenters, specifically claiming increased electricity demand and costs for consumers. While these campaigns didn’t gain significant traction, OpenAI’s investigation revealed insights into the narratives China is attempting to amplify.

Why It Matters

The reactivation of the JDY botnet represents a direct threat to US critical infrastructure. The botnet's focus on exploiting new vulnerabilities shortly after disclosure suggests a highly proactive and capable threat actor. For IT teams, this reinforces the critical importance of rapid patching and robust network security monitoring. The focus on the US military and related entities suggests a clear intelligence gathering objective.

The use of OpenAI’s ChatGPT for influence operations is also noteworthy. Although unsuccessful in this instance, it demonstrates a willingness to leverage Western technology for potentially malicious purposes. This highlights the dual-use dilemma inherent in advanced AI models and the challenges of mitigating their misuse. The attempt to influence the public debate on AI datacenters could be a precursor to more sophisticated campaigns aimed at hindering the development or deployment of AI technologies in the US.

What To Watch

It remains to be seen how effectively law enforcement and cybersecurity firms can contain the resurgent JDY botnet. Further analysis is needed to understand the full scope of compromised devices and the botnet's ultimate objectives. The OpenAI report suggests a continued effort by Chinese actors to exploit AI-generated content for influence operations, and security professionals should anticipate more sophisticated attempts in the future. It is also important to monitor whether the narratives tested in these initial campaigns evolve and gain traction over time. Enterprises should review CISA guidance for mitigating Volt Typhoon activity and defending against China-nexus covert networks, as detailed in the source article.

Source:

The Register ↗