JackSkid is an IoT-focused botnet malware family associated with large-scale distributed denial-of-service operations. It has been identified as part of a cluster of major botnets disrupted in a coordinated 2026 law-enforcement action alongside Aisuru, KimWolf, and Mossad. The malware targets internet-connected embedded devices, including routers, DVRs, IP cameras, and related IoT systems, and has been used to hijack large numbers of vulnerable devices for botnet activity.
JackSkid is notable both as an operational botnet in its own right and as part of the lineage for later malware. Researchers have described Dysphoria as evolving from JackSkid and fbot, inheriting code and behavior while adding more resilient command-and-control mechanisms, including blockchain-based infrastructure discovery and relay-node architectures. Reporting also indicates that after disruption pressure, JackSkid-related activity shifted toward more covert command-and-control resolution methods using blockchain naming services.
The botnet ecosystem around JackSkid has been linked to mass exploitation of weakly secured IoT devices, especially systems exposed with weak credentials or unpatched vulnerabilities. Its operational use is tied primarily to DDoS attacks, and court records cited in public reporting attribute tens of thousands of attack commands to the botnet. The broader cluster in which JackSkid operated collectively compromised millions of IoT devices worldwide, underscoring its role in industrialized DDoS-for-hire activity targeting organizations globally.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The disruption itself focused on seizing domains and backend systems used to coordinate the botnets, effectively cutting off the instructions that tell infected devices where and when to send traffic.
KimWolf and JackSkid targeted devices designed to be shielded from direct internet exposure, compromising and bringing them under the control of their operators.
После блокировки прежней инфраструктуры малварь стала получать адреса управляющих серверов через Ethereum Name Service (ENS), а в начале мая разработчики оснастили ботнет поддержкой Solana Name Service (SNS).
The infected devices were enslaved by the botnet operators. The operators then used a “cybercrime as a service” model to sell access to the infected devices to other cyber criminals.
This article provides an in-depth analysis of Dysphoria's historical evolution timeline, its core string decryption algorithm, its C2 infrastructure retrieval mechanism, its distinctive network proxy mechanism, sample propagation methods, infection scope, and DDoS attacks.
The KimWolf botnet, likely with the assistance of the Aisuru botnet, in December 2025 launched an attack against content delivery network Cloudflare that reached 31.4 terabits per seconds.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier botnet/malware lineage referenced as part of Dysphoria's evolution.
Previously known IoT malware/botnet family that Dysphoria is said to build upon; its infrastructure was targeted in a joint law-enforcement operation before Dysphoria adopted blockchain-based C2 discovery.
An earlier malware family from which Dysphoria evolved; its code and decryption logic are described as influencing later Dysphoria variants.
Related predecessor IoT botnet whose infrastructure disruption preceded Dysphoria's shift to ENS/SNS-based C2. Court documents attributed more than 90,000 DDoS commands to JackSkid alone.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.