JackSkid is an IoT-focused distributed-denial-of-service botnet, first documented in late 2025 and also tracked as RCtea. It targets Android and embedded Linux systems, including routers, DVRs, cameras, and other vulnerable connected devices. The botnet supports DDoS activity and has used Ethereum Name Service and Solana Name Service records for resilient command-and-control discovery. Later builds also used compromised residential devices as a relay layer for command-and-control traffic; some Android and Linux builds incorporated UPnP Internet Gateway Device port mapping to expose infected devices as directly reachable proxy exits.
JackSkid includes anti-competition functionality. Its 0clKiller component scans process information for rival malware and can monitor for newly created competing processes to terminate them rapidly. Researchers have linked portions of the JackSkid ecosystem with the peer4you-mirai hybrid botnet and trees4sale residential-proxy operation through shared relay code, configuration material, loaders, and infrastructure. JackSkid infrastructure was among the IoT botnet command-and-control systems disrupted in a multinational law-enforcement operation in March 2026. Dysphoria subsequently emerged as a related botnet lineage derived from JackSkid and fbot malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The disruption itself focused on seizing domains and backend systems used to coordinate the botnets, effectively cutting off the instructions that tell infected devices where and when to send traffic.
KimWolf and JackSkid targeted devices designed to be shielded from direct internet exposure, compromising and bringing them under the control of their operators.
The ONLINE telemetry is one-directional... the node advertises itself and waits for inbound connections on its mapped ports.
Scholl said Kimwolf was a novel botnet because it targeted residential proxy networks, infiltrating home networks through compromised devices — including streaming TV boxes and other IoT devices.
On startup the bot has the victim's own router open 165 ports, forwards them to the infected device, and labels every one RELAY. The residential exit is not hidden behind a tunnel; it is published on the home router's external interface.
On 23 July, a Jackskid Android APK ... changed shape: where earlier builds dropped a single DDoS bot, this one drops two binaries side by side.
The infected devices were enslaved by the botnet operators. The operators then used a “cybercrime as a service” model to sell access to the infected devices to other cyber criminals.
This article provides an in-depth analysis of Dysphoria's historical evolution timeline, its core string decryption algorithm, its C2 infrastructure retrieval mechanism, its distinctive network proxy mechanism, sample propagation methods, infection scope, and DDoS attacks.
The KimWolf botnet, likely with the assistance of the Aisuru botnet, in December 2025 launched an attack against content delivery network Cloudflare that reached 31.4 terabits per seconds.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet mentioned only as part of a separate law-enforcement disruption operation.
IoT botnet mentioned as one of several botnets whose infrastructure was disrupted.
Earlier botnet/malware lineage referenced as part of Dysphoria's evolution.
Previously known IoT malware/botnet family that Dysphoria is said to build upon; its infrastructure was targeted in a joint law-enforcement operation before Dysphoria adopted blockchain-based C2 discovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.