The Dysphoria Internet of Things (IoT) botnet has integrated blockchain-based name services and infected-device relays for its command-and-control (C2) infrastructure. This development follows a law enforcement operation in March that targeted JackSkid, a predecessor botnet.
Researchers from CNCERT, China's national computer emergency response team, and Qi'anxin's XLab, a threat-intelligence lab, have been tracking Dysphoria. They report that the botnet's design makes it more difficult to disrupt.
CNCERT and XLab estimate the Dysphoria botnet to comprise over 200,000 bots globally. Telemetry from July 14 to 20 recorded 4,401 active devices within China, with a single-day peak of 239,000 bots observed outside China. These numbers have not been independently verified, and the researchers did not publish their counting or de-duplication methodology.
The compromised devices are being utilized for distributed denial of service (DDoS) attacks and traffic relay operations.
Dysphoria evolved from the 'jackskid' and 'fbot' malware. The lineage includes JackSkid, which was one of four IoT botnets targeted in coordinated law enforcement actions by the U.S., Germany, and Canada on March 19. Court documents attributed over 90,000 DDoS commands to JackSkid alone.
XLab researchers first identified Dysphoria on March 25 and have noted multiple updates, including a C2 acquisition algorithm, multi-chain support, new domains, and functional separation between relaying and DDoS variants.
The botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information. C2 addresses are hidden within fake IPv6 strings and recovered using a custom byte-transformation algorithm. This use of blockchain in C2 operations makes the botnet's infrastructure more challenging to trace and dismantle, enhancing its resilience against disruption.
The frequent variant updates and technical iterations observed in Dysphoria demonstrate its strong resilience, according to XLab's report.
To mitigate risks from such botnets, defenders are advised to patch exposed IoT devices, replace devices that no longer receive updates, eliminate default and weak credentials, and disable remote management and UPnP when not essential.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Dysphoria botnet has infected approximately 200,000 devices worldwide, utilizing them for distributed denial of service (DDoS) attacks and traffic relay operations. This botnet employs a blockchain-based command-and-control (C2) mechanism, making its infrastructure more difficult to trace and dismantle.
The Dysphoria IoT botnet has integrated blockchain-based name services and infected-device relays for command-and-control (C2) following a March law enforcement operation against its predecessor, JackSkid. This architectural change makes the botnet more resilient to disruption by obscuring the location of its controllers.