jackskid_botnet
Jackskid Botnet is a Mirai-derived botnet active as of November 2025. The provided content describes it as a hybrid variant using Mirai’s core scanner with Rust-based modules for cross-architecture compilation across ARM, MIPS, and x86. It propagates through zero-day exploits and brute-force attacks, with reported infection volumes exceeding 40,000 devices daily. Reported targets include routers, DVRs, and industrial controllers, particularly in Asia-Pacific and North America. The content states that Jackskid used adaptive exploits including CVE-2024-3721 and CVE-2023-1389. Beyond DDoS activity, it is described as incorporating crypto-mining and data exfiltration for dual monetization. Additional techniques directly mentioned include custom UPX packing, RC4 string obfuscation, anti-analysis features, and XOR-encrypted IRC-like command-and-control over TCP/34125. The content also notes a November 2025 spike peaking at 45,000 bots on November 22. No high-confidence attribution to a specific nation state or named intrusion set is directly established in the provided content. Known alias in the content: jackskid_botnet.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.