Mossad is an Internet of Things botnet associated with large-scale distributed denial-of-service operations. It was identified alongside Aisuru, KimWolf, and JackSkid in a coordinated multinational law-enforcement disruption in March 2026. Authorities stated that these botnets collectively compromised more than three million devices worldwide, primarily IoT systems such as webcams, digital video recorders, IP cameras, and Wi-Fi routers, and were used to launch hundreds of thousands of DDoS attacks against victims globally, including targets associated with the U.S. Department of Defense Information Network.
Mossad is consistently described as part of the same DDoS botnet ecosystem as Aisuru, KimWolf, and JackSkid, and some reporting characterizes the cluster as Mirai-derived. Court filings and official statements attributed more than 1,000 DDoS attack commands to Mossad. The botnet’s operators were said to monetize access to infected devices through cybercrime-as-a-service activity, including DDoS-for-hire operations, and some attacks in this ecosystem were linked to extortion demands. Reporting also indicates Mossad competed with the related botnets for the same pool of vulnerable IoT devices.
Public reporting tied Mossad’s infrastructure disruption to seizures of command-and-control systems and related infrastructure in the United States, Canada, and Germany. Some investigative reporting assessed that Mossad was distinct from the Israeli intelligence service of the same name and may have been a separate project within the broader botnet milieu. High-confidence public information about Mossad’s standalone infection chain, persistence mechanisms, or platform-specific propagation beyond its role as an IoT DDoS botnet remains limited.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The disruption itself focused on seizing domains and backend systems used to coordinate the botnets, effectively cutting off the instructions that tell infected devices where and when to send traffic.
Devices infected by the four botnets include digital video recorders, web cameras, Wi-Fi routers and TV boxes.
The infected devices were enslaved by the botnet operators. The operators then used a “cybercrime as a service” model to sell access to the infected devices to other cyber criminals.
Kimwolf — DDoS-платформой, которую сдавали в аренду «по подписке» другим хакерам... ботнет использовался для проведения более чем 25 000 атак по всему миру... пиковая мощность отдельных атак достигала 31,4 Тбит/с.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoT botnet mentioned as one of several botnets whose infrastructure was disrupted.
Один из четырех DDoS-ботнетов, чья управляющая инфраструктура была отключена в ходе международной правоохранительной операции. Участвовал в заражении IoT-устройств.
Named as one of several high-impact IoT DDoS botnets disrupted through seizure of command-and-control infrastructure.
An IoT botnet disrupted in the same coordinated law-enforcement operation targeting DDoS botnets. The botnet was reported to have issued over 1,000 attack commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.