TF-MAL-elf.jackskid
📛 Threat Title
Malware family: Jackskid
Description
ThreatFox malware family `elf.jackskid`. Printable name: Jackskid. Aliases: RCtea.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:corporate.comcast.com
A new research report co-produced by the Comcast Threat Research Lab (CTRL) and the Nokia Deepfield Emergency Response Team (ERT), is revealing for the first time the secrets of Jackskid , a fast‑evolving botnet with unusual longevity and sophistication. While many malware operations flare up briefly and disappear, Jackskid has been continuously evolving for months, growing from a simple ...
-
web:foresiet.com
The Mirai botnet has resurged. Learn about the Jackskid variant, its 40,000+ active bots, and the critical IoT Threats.
-
web:github.com
A parallel ADB vector distributes com.system.update from 87.121.84 [.]74:13121 — a different malware family (Katana, a Mirai variant with on-device rootkit compilation) that shares infrastructure but not code with Jackskid .
-
web:github.com
Jackskid's residential proxy, brought to you by UPnP Nokia Deepfield Emergency Response Team (ERT)
-
web:hackmag.com
Law enforcement agencies in the US, Germany, and Canada conducted a joint operation and took down the command infrastructure of four major IoT botnets — Aisuru, Kimwolf, JackSkid , and Mossad.
-
web:krebsonsecurity.com
Some victims reported tens of thousands of dollars in losses and remediation expenses. The oldest of the botnets — Aisuru — issued more than 200,000 attacks commands, while JackSkid hurled at ...
-
web:malpedia.caad.fkie.fraunhofer.de
Jackskid is a Mirai-derived Linux/IoT DDoS botnet, first publicly documented by Foresiet in November 2025 and tracked by CNCERT/SecrSS as RCtea. It encrypts its configuration with a custom RC4 cipher post-processed by an LCG (key DEADBEEF CAFEBABE E0A4CBD6 BADC0DE5) and negotiates per-session ChaCha20 keys via XXTEA (passphrase FrshPckBnnnSplit).
-
web:thehackernews.com
Dysphoria adds blockchain C2 and victim relays after the JackSkid disruption, keeping controllers one step removed from addresses exposed to bots.
-
web:www.justice.gov
ANCHORAGE, Alaska - The U.S. Justice Department participated in a court-authorized law enforcement operation today to disrupt Command and Control (C2) infrastructure used by the Aisuru, KimWolf, JackSkid and Mossad Internet of Things (IoT) botnets.
-
web:www.mallory.ai
JackSkid is an Internet of Things (IoT) botnet used to conduct distributed denial-of-service (DDoS) attacks. In March 2026, U.S., German, and Canadian authorities disrupted command-and-control infrastructure associated with JackSkid alongside the related botnets Aisuru, KimWolf, and Mossad.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.