Actor Profile

JackSkid is an IoT botnet operator linked to the Dysphoria botnet family, targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026. Court documents attributed over 90,000 DDoS commands to JackSkid infrastructure prior to disruption. The operator's motivation centers on DDoS-for-hire services, advertising attacks up to 4 Tbps for tens to hundreds of dollars. Following takedown, the actor rapidly evolved infrastructure to use blockchain-based name services (Ethereum Name Service and Solana Name Service) and victim-device relay meshes to evade future law enforcement action. No individual operator has been publicly identified by researchers. The botnet shares code and strings with several other IoT botnet families including Kimwolf and AISURU, suggesting shared tooling across multiple operators in the Chinese IoT botnet ecosystem.

TTPs (Tactics, Techniques, Procedures)

Initial Access: Telnet and SSH weak-password brute-forcing (T1078), exploitation of known IoT remote-code-execution vulnerabilities including CVE-2025-9528 (Linksys E1700 command injection) targeting routers, gateways, and cameras (T1190). Command and Control: Blockchain-based domain resolution via Ethereum Name Service (ENS) and Solana Name Service (SNS) for C2 infrastructure (T1071.001), HTTP-based distribution node queries for dynamic server lists, victim-device relay mesh to obfuscate controller locations. Persistence: UPnP-based port mapping to traverse NAT gateways (T1599), Linux epoll for traffic relaying. Defense Evasion: Custom RC4 string encryption (T1027), multi-layer relay architecture separating controllers from exposed bot-facing infrastructure. Impact: DDoS attacks against internet-service and gaming targets (T1498, T1499), operator claims of 4 Tbps attack capacity.

Targets & Patterns

JackSkid primarily targets Internet of Things devices and critical infrastructure sectors. Victim devices include routers, gateways, and IP cameras from multiple vendors, with specific focus on devices with weak or default credentials and unpatched vulnerabilities. CNCERT and XLab telemetry logged 4,401 confirmed active infected devices inside China between July 14-20, 2026, with a single-day peak of 239,000 bots internationally, suggesting global targeting with concentration in Asia-Pacific. The botnet population is estimated above 200,000 devices, though counting methodology was not disclosed. Attack targets include internet service providers and gaming platforms, consistent with DDoS-for-hire business model. The targeting pattern reflects opportunistic exploitation of poorly secured IoT infrastructure rather than strategic victim selection, with the operator monetizing access through underground DDoS services marketed to cybercriminals seeking disruption capabilities.

Historical Context

JackSkid was one of four IoT botnets disrupted in coordinated law enforcement operations by U.S., German, and Canadian authorities on March 19, 2026. Within days of the takedown, Nokia Deepfield and Comcast threat labs documented the operator pivoting to Ethereum Name Service domain m3rnbvs5d[.]eth for C2. XLab captured the first post-disruption Dysphoria sample on March 25, 2026, six days after law enforcement action, using the same ENS domain. The botnet underwent rapid evolution: custom RC4 encryption and ENS resolution by end of April, Solana Name Service integration in early May, and relay-only variants with UPnP port mapping by late June 2026. Japan's NICT independently confirmed the JackSkid-to-ENS/SNS transition in May 2026. XLab previously documented the related Kimwolf botnet using ENS-based C2 in late 2025. Cloudflare measured a 31.4 Tbps attack from the related AISURU/Kimwolf botnet before the March disruption, demonstrating the ecosystem's significant DDoS capacity. Code and string overlap across multiple botnet families suggests shared tooling within the Chinese IoT botnet landscape.

Defensive Recommendations

  • Patch all exposed IoT devices immediately, prioritize CVE-2025-9528 (Linksys E1700) and other known RCE vulnerabilities in routers, gateways, and cameras; replace end-of-life devices that cannot receive security updates
  • Eliminate default credentials and enforce strong password policies on all Telnet and SSH services; disable Telnet entirely where SSH can be used; monitor for T1078 credential brute-force attempts via failed authentication logs
  • Disable remote management interfaces and UPnP on IoT devices where not operationally required; implement network segmentation to isolate IoT devices from critical systems and monitor for T1599 UPnP port mapping activity
  • Monitor DNS queries to blockchain name services (ENS .eth domains, SNS .sol domains) and block resolution of known malicious records (m3rnbvs5d[.]eth, burrberry[.]eth, 24carnforth2merseyside[.]sol) at recursive resolvers
  • Deploy network behavioral analytics to detect T1498/T1499 DDoS traffic patterns, unusual outbound HTTP requests to distribution nodes, and Linux epoll-based relay traffic indicative of compromised devices participating in relay mesh infrastructure

---

# Geopolitical Context

Geopolitical Context

The evolution of the Dysphoria IoT botnet following the March 2026 coordinated U.S., German, and Canadian law enforcement operation against JackSkid infrastructure illustrates the adaptive resilience of cybercriminal ecosystems. The rapid architectural shift—from centralized command-and-control to blockchain-based name services (Ethereum Name Service and Solana Name Service) combined with victim-device relay networks—demonstrates sophisticated counter-law-enforcement tradecraft. This case reflects a broader trend in which botnet operators leverage decentralized technologies to complicate attribution and interdiction. The disclosure by CNCERT and XLab, both Chinese entities, provides rare technical transparency from China's cyber defense sector, though the research names no operator and offers no attribution. The botnet's targeting of internet-service and gaming infrastructure, combined with its advertised 4 Tbps DDoS capacity, positions it as a persistent threat to critical digital services globally.

State Actor Alignment

No state actor is attributed or linked to the Dysphoria botnet in available reporting. CNCERT and XLab's joint analysis focuses on technical architecture and does not assign operator identity or sponsorship. The March 2026 law enforcement action against the predecessor JackSkid botnet involved U.S., German, and Canadian authorities, indicating Western coordination against IoT-based DDoS infrastructure. Court documents attributed over 90,000 DDoS commands to JackSkid, but no individual or group has been publicly charged or named. The use of blockchain name services and victim relays appears consistent with cybercriminal innovation rather than state-directed operations, though the absence of operator attribution leaves this assessment tentative. Independent researchers from Japan's NICT and private-sector entities (Nokia Deepfield, Comcast, Cloudflare) have corroborated technical elements but have not identified a controlling entity.

Business Impacty pro region

The botnet's global footprint—with a reported single-day peak of 239,000 devices abroad and over 4,400 active bots inside China—underscores the transnational nature of IoT exploitation. European infrastructure remains vulnerable given the botnet's exploitation of unpatched routers, gateways, and cameras, many of which are legacy devices no longer receiving vendor updates. The March law enforcement action, which included German participation, reflects European engagement in countering DDoS-for-hire services, yet the rapid reconstitution of the botnet suggests that operational disruption alone is insufficient without parallel efforts to harden the IoT device base. The botnet's targeting of internet-service and gaming sectors may affect European digital service providers, particularly those with inadequate DDoS mitigation. The use of decentralized blockchain infrastructure complicates traditional takedown mechanisms that rely on domain seizures or server interdiction, potentially requiring new legal and technical frameworks for cross-border enforcement. The disclosure by Chinese entities may signal growing alignment between Chinese and Western cyber defense priorities regarding botnet threats, though no formal cooperation is evident in public reporting.

Forecast

If botnet operators continue to adopt blockchain-based C2 and victim-relay architectures, law enforcement and private-sector defenders will likely face increased difficulty in executing traditional takedown operations, necessitating investment in alternative disruption methods such as sinkholing blockchain name service records or coordinated relay-node remediation. If the reported 200,000-device scale is accurate and the botnet sustains its operational tempo, DDoS attacks against internet-service and gaming targets are likely to persist at scale, with potential spillover effects on adjacent critical infrastructure. If vendors do not accelerate security updates for legacy IoT devices—particularly routers and cameras exploited via known CVEs such as CVE-2025-9528—the pool of recruitable devices will remain large, enabling continued botnet growth. If Western and Chinese cyber defense entities increase information-sharing on IoT threats, as suggested by CNCERT and XLab's public disclosure, coordinated mitigation efforts may become more feasible, though formal mechanisms for such cooperation remain absent. If no operator is identified or prosecuted, the deterrent effect of the March law enforcement action will likely diminish, encouraging further innovation in resilient botnet design.