JackSkid, also referred to as jackskid_botnet and tracked by CNCERT as RCtea, is a financially motivated cybercriminal botnet operation documented since November 2025. It uses Mirai-derived malware to compromise internet-connected devices and monetize them through DDoS-for-hire and residential proxy services. Its operators' identities and country of origin are not established. U.S. authorities attributed approximately 90,000 DDoS attacks to JackSkid, including attacks against the U.S. Department of Defense Information Network. JackSkid belongs to the Aisuru malware development lineage and uses a modified RC4 algorithm for configuration obfuscation. Its infrastructure uses Ethereum Name Service and Solana Name Service dead-drop records to resolve command-and-control destinations, reducing dependence on conventional DNS. Compromised residential devices also serve as a rotating C2 relay network. The operation is linked to the peer4you-mirai hybrid malware and trees4sale residential proxy family through shared relay code, configuration keys, delivery infrastructure, and blockchain funding relationships. These are related malware operations rather than established aliases for JackSkid. The associated hybrid malware retains Mirai-style Telnet scanning and default-credential brute forcing. Its proxy component abuses UPnP Internet Gateway Device port mapping to expose infected residential devices directly as internet-accessible proxy exits, opening 165 external router ports. Some JackSkid Android builds deploy separate DDoS and proxy-relay payloads, while Linux ARM and MIPS builds integrate the relay into the DDoS binary. An international law-enforcement operation involving the United States, Canada, and Germany disrupted JackSkid's command-and-control infrastructure in March 2026 alongside Aisuru, KimWolf, and Mossad. JackSkid subsequently regrouped, with renewed activity documented in mid-2026.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet network disrupted by the US Department of Justice.
Botnet used for large-scale DDoS attacks; described as particularly sneaky because it could infect devices traditionally hidden behind firewalls and was rented to other hackers.
Botnet operation involved in DDoS activity; the content says JackSkid was responsible for about 90,000 DDoS attacks.
Botnet involved in distributed-denial-of-service attacks using infected Internet-of-Things devices worldwide.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.