Skynet is the name assigned by its apparent author to a Windows malware proof-of-concept submitted in June 2025. It is notable for embedding a prompt-injection message intended to cause LLM-based malware-analysis tooling to disregard its analysis instructions and return a benign verdict. Tests against OpenAI o3 and GPT-4.1 showed that this specific injection attempt was not successful. The sample uses layered XOR and Base64 obfuscation, opaque control flow, and checks associated with debuggers, virtual machines, and sandbox environments. It attempts to collect SSH-related material and host-configuration data, but writes the gathered data to standard output rather than implementing confirmed exfiltration. It also decrypts and launches an embedded Tor client configured as a local proxy, then removes its temporary working material. The sample appears incomplete and is assessed as experimental rather than a mature operational implant. The Skynet name has also been used independently for an older Tor-enabled IRC botnet incorporating DDoS, banking-trojan, proxy, and cryptocurrency-mining functions; those historical capabilities should not be attributed to the 2025 proof-of-concept solely on the basis of the shared name.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AnonSudan accepted orders over the instant messaging service Telegram, and marketed its DDoS service by several names, including “Skynet,” “InfraShutdown,” and the “Godzilla botnet.”
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Amazon said AnonSudan launched its attacks by finding hosting companies that would rent them small armies of servers.
Specifically, the warrants authorized the seizures of computer servers that launched and controlled the DDoS attacks, computer servers that relayed attack commands to a broader network of attack computers, and accounts containing the source code for the DDoS tools used by Anonymous Sudan.
Код обфусцирован побайтовым XOR с ротацией и 16-байтным хардкодированным ключом; payload дополнительно закодирован в base64.
The malware contains an encrypted embedded PE binary, which can be extracted. It will be written on the host, named skynet... The main uses XOR — with the same key — to decrypt an embedded binary... The result will be written to the filesystem, in a temporary directory, with name skynet.
В материале XOR/base64-обфускация отнесена к Obfuscated Files or Information (T1027) с элементами Command Obfuscation (T1027.010).
"resulting in the end with the core being disguised either as Internet Explorer or as svchost.exe"
Embedded in the C++ was an instruction addressed to whatever model came to analyze the file, telling it to ignore its previous instructions and report the binary as clean.
При запуске образец проверяет запуск из временной директории — индикатор sandbox-окружения; также описаны шесть функций антисандбокса.
Reads the registry (Hardware\Description\System\BIOS) and checks for specific BIOS vendor signatures... In the registry (System\CurrentControlSet\Services\disk\Enum), searches for specific names like VMware, VBOX or QEMU.
"Get information on the compromised computer !info, !version, !hardware, !idle"
«Сбор содержимого чувствительных директорий — результаты выводятся в stdout, но не эксфильтрируются».
При запуске образец проверяет запуск из временной директории — индикатор sandbox-окружения; также описаны шесть функций антисандбокса.
The malware may contact 2 different onion URLs: s4k4ceiapwwgcm3mkb6e4diqecpo7kvdnfr5gg7sph7jjppqkvwwqtyd.onion, port 8080 ... and zn4zbhx2kx4jtcqexhr5rdfsj4nrkiea4nhqbfvzrtssakjpvdby73qd.onion on port 31068.
«Расшифровка встроенного Tor-клиента, запуск прокси через CreateProcessA на указанных портах».
"it's requesting them to a proxy running locally... This proxy then translates the request to a specific Tor .onion pseudo-domain and tunnel the requests through the Tor SOCKS proxy"
Skynet was more like a “distributed cloud attack tool,” with a command and control (C2) server, and an entire fleet of cloud-based servers that forwards C2 instructions to an array of open proxy resolvers run by unaffiliated third parties, which then transmit the DDoS attack data to the victims.
"embeds the CGMiner... starts mining bitcoins only after two minutes of inactivity and immediately stops when some monitored event occurs"
Anonymous Sudan ... is a cybercrime business known for launching powerful distributed denial-of-service (DDoS) attacks against a range of targets, including dozens of hospitals, news websites and cloud providers.
CrowdStrike said the success of AnonSudan’s DDoS attacks stemmed from a combination of factors, including sophisticated techniques for bypassing DDoS mitigation services. Also, AnonSudan typically launched so-called “Layer 7” attacks that sought to overwhelm targeted “API endpoints” ... with bogus requests for data, leaving the target unable to serve legitimate visitors.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Incomplete proof-of-concept malware sample that uses XOR/Base64 obfuscation, anti-debugging and sandbox-evasion checks, collects contents of sensitive directories to stdout, decrypts and launches an embedded Tor client/proxy, and removes its temporary directory. Its distinguishing feature is an embedded prompt-injection string intended to manipulate LLM-based malware-analysis tools into reporting that no malware was detected.
A malware sample containing embedded prompt-injection instructions intended to mislead AI-based malware analysis systems into reporting the binary as clean.
Skynet is a malware strain designed to test prompt injection against AI-powered malware analysis systems. It embeds malicious instructions intended to manipulate LLM-based security tools into misclassifying the sample as benign, though researchers described it as an experimental proof-of-concept rather than a fully functional threat deployment.
A rudimentary malware component/proof-of-concept that performs sandbox/VM evasion checks, collects local files (including SSH known_hosts and id_rsa, and the Windows hosts file), prints the collected data to stdout, and decrypts/drops an embedded Tor client to set up a local SOCKS/ControlPort proxy before wiping its temp directory. It also contains an attempted LLM prompt-injection string intended to manipulate AI-assisted analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.