Dysphoria IoT Botnet Adopts Blockchain C2 After JackSkid Disruption
The Dysphoria Internet of Things (IoT) botnet, tracked by CNCERT and XLab, has integrated blockchain-based name services and infected-device relays following a law enforcement operation against the JackSkid infrastructure in March. This development makes the botnet more resilient to disruptions. The botnet's population is estimated to exceed 200,000 bots, with significant activity recorded both in China and internationally. The botnet employs Ethereum Name Service (ENS) domains for command-and-control (C2) operations, complicating traditional server seizure efforts. Dysphoria spreads through weak Telnet and SSH credentials and exploits known IoT vulnerabilities, such as the Linksys E1700 command-injection flaw. The botnet targets internet-service and gaming sectors, advertising attacks of up to 4 Tbps.