JackSkid is an IoT-focused distributed denial-of-service botnet malware family active since at least late 2025 and associated with large-scale compromise of embedded devices such as routers, DVRs, IP cameras, and other Linux-based or Android-based systems. It has been tracked as a DDoS botnet and has also been linked to a broader malware ecosystem that blends attack infrastructure with residential proxy and relay functionality. JackSkid has been identified as one of several major IoT botnets disrupted in a coordinated law-enforcement action in March 2026 alongside AISURU, KimWolf, and Mossad.
JackSkid is notable for combining conventional botnet behavior with resilient command-and-control techniques and relay-node abuse. Reported variants use blockchain-based naming systems, including Ethereum Name Service and Solana Name Service, to resolve command-and-control infrastructure, reducing dependence on ordinary DNS. Some builds retrieve lists of intermediary relay nodes and route bot communications through compromised residential devices, helping conceal the real controllers and complicate takedown efforts. Research has also placed JackSkid in the AISURU development lineage based on shared cryptographic and implementation traits.
The malware’s primary role is DDoS activity, but later builds and closely linked components also expose infected devices as proxy or relay nodes. Observed Linux and Android variants abuse UPnP Internet Gateway Device functionality on local routers to create large numbers of external port mappings, making compromised hosts directly reachable from the internet despite NAT. In some cases, relay functionality was delivered as a second Android payload; in others, it was compiled directly into Linux DDoS binaries. This architecture allows infected residential devices to serve simultaneously as attack bots, command relays, or proxy exits.
JackSkid has been linked by multiple technical overlaps to related malware and services including peer4you-mirai, trees4sale, and the later Dysphoria botnet lineage. Dysphoria is widely described as having evolved from JackSkid and fbot, adding stronger resilience mechanisms, blockchain-based C2 discovery, and relay-focused variants. These relationships indicate that JackSkid is part of an actively iterated ecosystem rather than an isolated family.
Targeting has centered on vulnerable IoT and embedded devices. Reported infection and propagation activity in the surrounding lineage includes exploitation of weak Telnet credentials, weak SSH credentials, and known vulnerabilities in routers and other internet-exposed appliances. High-confidence reporting also ties the broader cluster to brute-force scanning behavior in some related variants. Overall, JackSkid represents a modern IoT botnet family that combines DDoS capability, relay/proxy abuse, NAT traversal through UPnP, and resilient C2 design to sustain operations against disruption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The disruption itself focused on seizing domains and backend systems used to coordinate the botnets, effectively cutting off the instructions that tell infected devices where and when to send traffic.
KimWolf and JackSkid targeted devices designed to be shielded from direct internet exposure, compromising and bringing them under the control of their operators.
The ONLINE telemetry is one-directional... the node advertises itself and waits for inbound connections on its mapped ports.
Scholl said Kimwolf was a novel botnet because it targeted residential proxy networks, infiltrating home networks through compromised devices — including streaming TV boxes and other IoT devices.
On startup the bot has the victim's own router open 165 ports, forwards them to the infected device, and labels every one RELAY. The residential exit is not hidden behind a tunnel; it is published on the home router's external interface.
On 23 July, a Jackskid Android APK ... changed shape: where earlier builds dropped a single DDoS bot, this one drops two binaries side by side.
The infected devices were enslaved by the botnet operators. The operators then used a “cybercrime as a service” model to sell access to the infected devices to other cyber criminals.
This article provides an in-depth analysis of Dysphoria's historical evolution timeline, its core string decryption algorithm, its C2 infrastructure retrieval mechanism, its distinctive network proxy mechanism, sample propagation methods, infection scope, and DDoS attacks.
The KimWolf botnet, likely with the assistance of the Aisuru botnet, in December 2025 launched an attack against content delivery network Cloudflare that reached 31.4 terabits per seconds.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoT botnet mentioned as one of several botnets whose infrastructure was disrupted.
Earlier botnet/malware lineage referenced as part of Dysphoria's evolution.
Previously known IoT malware/botnet family that Dysphoria is said to build upon; its infrastructure was targeted in a joint law-enforcement operation before Dysphoria adopted blockchain-based C2 discovery.
An earlier malware family from which Dysphoria evolved; its code and decryption logic are described as influencing later Dysphoria variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.