What's Happening?
The Dysphoria Internet of Things (IoT) botnet, tracked by CNCERT and XLab, has integrated blockchain-based name services and infected-device relays following a law enforcement operation against the JackSkid infrastructure in March. This development makes
the botnet more resilient to disruptions. The botnet's population is estimated to exceed 200,000 bots, with significant activity recorded both in China and internationally. The botnet employs Ethereum Name Service (ENS) domains for command-and-control (C2) operations, complicating traditional server seizure efforts. Dysphoria spreads through weak Telnet and SSH credentials and exploits known IoT vulnerabilities, such as the Linksys E1700 command-injection flaw. The botnet targets internet-service and gaming sectors, advertising attacks of up to 4 Tbps.
Why It's Important?
The adoption of blockchain-based C2 by the Dysphoria botnet represents a significant evolution in cyber threats, making it more challenging for cybersecurity professionals to disrupt its operations. This shift underscores the increasing sophistication of cybercriminals in leveraging decentralized technologies to evade detection and maintain control over large botnets. The impact on U.S. industries, particularly those reliant on IoT devices, could be substantial, as these botnets can launch large-scale distributed denial-of-service (DDoS) attacks, potentially disrupting services and causing financial losses. The need for robust cybersecurity measures and updated IoT device management is more critical than ever to protect against such threats.
What's Next?
Organizations are advised to patch exposed IoT devices, replace outdated equipment, and strengthen security protocols to mitigate the risk posed by botnets like Dysphoria. The cybersecurity community will likely continue to monitor and develop strategies to counteract the evolving tactics of such botnets. Law enforcement agencies may also increase international cooperation to address the cross-border nature of these cyber threats. The ongoing development of blockchain-based C2 systems will require new approaches to cybersecurity, potentially leading to innovations in threat detection and response.











