Threat Intelligence
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Cyber RTJuly 27, 20263 min read

Dysphoria, an IoT botnet tracked by CNCERT and XLab, uses blockchain-based name services to enhance resilience post-law enforcement actions against JackSkid. With over 200,000 bots, it spreads via weak Telnet and SSH credentials and IoT vulnerabilities. The botnet's design complicates disruption by using infected-device relays and blockchain records. Despite claims of large-scale attacks, independent verification of Dysphoria's impact remains absent.
The Dysphoria botnet, an Internet of Things (IoT) network tracked by CNCERT and XLab, has evolved by integrating blockchain-based name services and infected-device relays. This development follows a law enforcement operation in March targeting JackSkid infrastructure, making the botnet more resilient and harder to disrupt. CNCERT, China's national computer emergency response team, and XLab, a threat-intelligence lab of Qi'anxin, estimate the botnet's population to exceed 200,000 bots, with significant activity both within China and internationally.
The researchers' telemetry recorded 4,401 active devices in China from July 14 to 20 and a peak of 239,000 bots abroad in a single day. However, these figures have not been independently verified, and the methodology for counting or de-duplication was not disclosed, suggesting that the numbers should not be taken as precise. To combat such threats, defenders are advised to patch exposed IoT devices, replace outdated equipment, eliminate weak credentials, and disable unnecessary remote management features.
The Dysphoria botnet's lineage can be traced back to JackSkid, one of four IoT botnets targeted by coordinated law enforcement actions in March across the U.S., Germany, and Canada. JackSkid was responsible for over 90,000 DDoS commands. Following the crackdown, the botnet operators quickly adapted by utilizing an Ethereum Name Service (ENS) domain for command-and-control (C2) operations, as documented by Nokia Deepfield and Comcast's threat lab.
XLab's analysis reveals that the botnet uses blockchain records to encode distribution-node IP addresses and other infrastructure records. The design involves infected machines acting as relays, keeping the real controllers hidden from direct exposure. This setup complicates efforts to seize servers, as the botnet relies on a mesh of compromised devices to relay traffic to its controllers.
The botnet has undergone rapid development, with XLab tracking new builds featuring custom RC4 string encryption and ENS resolution. In May, the botnet incorporated Solana Name Service (SNS) resolution, and by June, a relay-only variant emerged, utilizing UPnP-based port mapping to navigate NAT gateways. This variant drops DDoS modules, focusing instead on using UPnP and Linux epoll for traffic relay.
Despite these advancements, the botnet's infrastructure still depends on blockchain records, reachable distribution nodes, and compromised relays. Japan's NICT independently confirmed the shift to ENS/SNS in May and noted shared code and strings with other botnet families, indicating shared tooling rather than a single operator. Dysphoria spreads through weak Telnet and SSH credentials and exploits known IoT vulnerabilities, such as the CVE-2025-9528 flaw in Linksys E1700 routers.
XLab and CNCERT report that Dysphoria frequently targets internet-service and gaming sectors, though specific victims or attack peaks are not disclosed. The botnet's operators claim to offer attacks of up to 4 Tbps for a fee, but these claims lack independent verification. Cloudflare recorded a 31.4 Tbps attack from the related AISURU/Kimwolf botnet before the March disruption, but no independent source has confirmed Dysphoria's reported scale or attack peaks.


