New, from our ERT: Most residential proxy malware hides the exit behind an outbound tunnel. This one has the victim’s own router open 165 ports over UPnP and labels every mapping RELAY. Telemetry on the proxy domains led us back to #Jackskid, a DDoS botnet we have tracked since late 2025. Same operator behind all of it: a pure relay family, a Mirai bot that moonlights as one, and Jackskid, which now compiles the relay straight in. https://github.com/deepfield/public-research/blob/main/reports/2026-07-24-jackskid-residential-proxy-upnp.md #threatintel #tree4sale #peer4you