JackSkid is an IoT DDoS botnet malware family documented since late 2025, also tracked by CNCERT as RCtea. It belongs to the Aisuru development lineage and operates on Android devices and embedded Linux systems, including ARM and MIPS platforms. Its distribution has exploited weaknesses in residential-proxy services that allow attackers to reach local-network devices, including Android systems with exposed Android Debug Bridge services.
JackSkid combines DDoS functionality with aggressive competitor removal and increasingly resilient command-and-control infrastructure. Its 0clKiller module examines running processes to identify competing malware; later versions added a NETLINK process monitor to terminate newly launched competitors within milliseconds. The family uses a modified RC4 algorithm for configuration protection and Ethereum Name Service and Solana Name Service records for C2 discovery. Compromised residential devices also form a rotating C2 relay mesh, insulating the underlying controllers from direct exposure.
Some Android builds deploy a separate residential-proxy relay alongside the DDoS payload, while later Linux builds integrate relay functionality directly. This component abuses UPnP Internet Gateway Device port mapping to open 165 external ports on the local router, making infected devices directly reachable as residential proxy exits. Shared relay code, configuration cryptography, and infrastructure link JackSkid to the peer4you-mirai hybrid botnet and trees4sale proxy family under a common, publicly unnamed operator. JackSkid also contributed to the malware lineage from which Dysphoria evolved.
Authorities in the United States, Germany, and Canada disrupted JackSkid C2 infrastructure on March 19, 2026, alongside Aisuru, Kimwolf, and Mossad. JackSkid subsequently regrouped and continued developing its relay and blockchain-based C2 mechanisms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The disruption itself focused on seizing domains and backend systems used to coordinate the botnets, effectively cutting off the instructions that tell infected devices where and when to send traffic.
KimWolf and JackSkid targeted devices designed to be shielded from direct internet exposure, compromising and bringing them under the control of their operators.
The ONLINE telemetry is one-directional... the node advertises itself and waits for inbound connections on its mapped ports.
Scholl said Kimwolf was a novel botnet because it targeted residential proxy networks, infiltrating home networks through compromised devices — including streaming TV boxes and other IoT devices.
On startup the bot has the victim's own router open 165 ports, forwards them to the infected device, and labels every one RELAY. The residential exit is not hidden behind a tunnel; it is published on the home router's external interface.
On 23 July, a Jackskid Android APK ... changed shape: where earlier builds dropped a single DDoS bot, this one drops two binaries side by side.
The infected devices were enslaved by the botnet operators. The operators then used a “cybercrime as a service” model to sell access to the infected devices to other cyber criminals.
Synthient’s Research Team assesses that IPWeb has directly enabled the spread of DDoS botnets, including Jackskid, Katana, and SDKC.
The KimWolf botnet, likely with the assistance of the Aisuru botnet, in December 2025 launched an attack against content delivery network Cloudflare that reached 31.4 terabits per seconds.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kimwolf-inspired botnet exploiting weaknesses in residential proxy SDKs. The article attributes about 90,000 attack commands to it and reports infrastructure seizure alongside Aisuru and Kimwolf in March 2026.
A named DDoS botnet that the report assesses was enabled to spread through IPWeb's proxy infrastructure.
A botnet mentioned only as part of a separate law-enforcement disruption operation.
IoT botnet mentioned as one of several botnets whose infrastructure was disrupted.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.