JackSkid is a Mirai-derived botnet and cybercrime operation associated with large-scale distributed denial-of-service activity and related monetization through compromised internet-connected devices. It has been tracked since late 2025 and was disrupted in a March 2026 international law-enforcement action alongside Aisuru, KimWolf, and Mossad, but later reconstituted. JackSkid has been linked to the broader Aisuru development lineage and has also been tracked under the name RCtea. Available reporting further links JackSkid to the peer4you-mirai hybrid malware and the trees4sale residential proxy service, indicating a single operator or tightly connected operator cluster behind DDoS, proxy, and relay activity. The operation primarily compromises residential and small-office devices and has also targeted Android-based systems. It uses Mirai-style scanning and brute-force tradecraft, including telnet-oriented propagation inherited through related tooling, and has been reported as capable of reaching devices normally shielded behind firewalls. More recent variants use decentralized dead-drop mechanisms through blockchain naming services for command-and-control resolution rather than relying solely on conventional DNS. JackSkid also uses compromised residential devices as a rotating relay mesh for command-and-control, and some builds expose infected devices directly to the internet by abusing UPnP Internet Gateway Device port mapping on victim routers. This relay functionality overlaps with the trees4sale and peer4you malware families and supports both proxying and botnet operations. JackSkid is not limited to DDoS. Reported builds have incorporated crypto-mining and data exfiltration, making it a hybrid monetization platform rather than a pure flood bot. Reverse-engineering cited in the reporting describes Rust-based modules supporting cross-architecture deployment across ARM, MIPS, and x86 environments. Android-delivered variants have also been observed dropping both a DDoS payload and a second relay payload, while later Linux samples compiled relay logic directly into the bot. Shared cryptographic configuration material, shared loader infrastructure, shared relay code, and co-hosted infrastructure strongly connect JackSkid with peer4you-mirai and trees4sale. Operationally, JackSkid has been used in a cybercrime-as-a-service model to rent attack capacity to other criminals. By March 2026, authorities attributed roughly 90,000 DDoS attacks to the botnet as part of a larger cluster that had compromised millions of devices globally. High-confidence reporting supports DDoS, brute-force propagation, residential proxy abuse, command-and-control relay through infected hosts, persistence through continued retooling after disruption, and monetization through both attack-for-hire and ancillary criminal services. The actor is best characterized as financially motivated cybercrime rather than a state-sponsored intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named botnet network disrupted by the US Department of Justice.
Botnet used for large-scale DDoS attacks; described as particularly sneaky because it could infect devices traditionally hidden behind firewalls and was rented to other hackers.
Botnet operation involved in DDoS activity; the content says JackSkid was responsible for about 90,000 DDoS attacks.
Botnet involved in distributed-denial-of-service attacks using infected Internet-of-Things devices worldwide.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.