Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Dysphoria IoT Botnet Evolution: A Complex Web of Blockchain C2 and Victim Relays




In a significant development, the Dysphoria IoT botnet has evolved by adopting blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. This evolution makes it harder to disrupt the botnet, but researchers have identified several vulnerabilities that could be exploited to stop its spread.

The botnet is believed to have a population of over 200,000 devices, with attacks targeting internet services and gaming platforms almost daily. However, no confirmed victims or measured attack peaks have been reported. The attackers use weak Telnet and SSH credentials as the primary entry point, making it essential for defenders to patch exposed IoT gear, replace devices that can no longer be updated, eliminate default and weak credentials, and disable remote management and UPnP where they are not needed.



  • The Dysphoria IoT botnet has a population of over 200,000 infected devices.
  • The botnet uses blockchain-based name services and infected-device relays to evade law enforcement.
  • Dysphoria is believed to have originated from JackSkid infrastructure targeted in March operations.
  • The botnet uses various vulnerabilities, including Telnet and SSH weak-password guessing and known IoT remote-code-execution flaws.
  • Attack peaks are unknown, but the operator claims attacks of up to 4 Tbps can be launched for tens to hundreds of dollars.



  • The world of cybersecurity has witnessed the rise and fall of various botnets over the years, but none as intriguing as the Dysphoria IoT botnet. This particular threat actor has managed to outsmart law enforcement agencies by adopting blockchain-based name services and infected-device relays after a March operation against JackSkid infrastructure. The researchers at CNCERT and XLab have been tracking this botnet line, which they claim has a population of over 200,000 devices.

    According to the report, Dysphoria's lineage runs through JackSkid, one of four IoT botnets targeted in coordinated U.S., German, and Canadian law-enforcement actions on March 19. Court documents attributed more than 90,000 DDoS commands to JackSkid alone. Within days, Nokia Deepfield and Comcast's threat lab documented the operator falling back to an Ethereum Name Service (ENS) domain, m3rnbvs5d[.]eth, for command-and-control (C2).

    XLab found that the burrberry[.]eth record encodes distribution-node IPv4 addresses, while 24carnforth2merseyside[.]sol supplies other infrastructure records. The DDoS sample asks a distribution node over HTTP for a current server list, and the listed endpoints are infected machines relaying traffic to the real controllers. The design keeps those controllers one step removed from the addresses exposed to bots.

    The XLab analysis tracks a fast run of builds: custom RC4 string encryption and ENS resolution at the end of April, followed by Solana Name Service (SNS) resolution in early May. A relay-only variant appeared on June 25, with UPnP-based port mapping added days later to traverse NAT gateways.

    The shift complicates a conventional server seizure, but it does not remove infrastructure from the chain: the botnet still depends on blockchain records, reachable distribution nodes, and compromised relays. Japan's NICT independently documented the same JackSkid-to-ENS/SNS shift in May, and, like Nokia and Comcast, found code and strings shared with several other botnet families.

    The researchers at XLab and CNCERT say Dysphoria spreads through Telnet and SSH weak-password guessing and a set of known IoT remote-code-execution flaws in routers, gateways, and cameras. One example present in both published lists is CVE-2025-9528, a Linksys E1700 command-injection flaw disclosed in August 2025 with a public exploit.

    The vendor did not respond to the original report. NVD's CVSS vector rates the flaw as requiring high privileges, and neither publication explains how it fits the botnet's propagation chain. A comparison by The Hacker News found that XLab's post and a mirrored CNCERT notice publish different vulnerability lists despite presenting the same joint research.

    Both agree that weak Telnet and SSH credentials remain the most consistent way in. XLab says Dysphoria attacks internet-service and gaming targets almost daily, but it names no victims or measured peaks. The storefront advertises attacks of up to about 4 Tbps for tens to hundreds of dollars, but that is an operator claim, not a measured attack.

    Cloudflare measured a 31.4 Tbps attack from the related AISURU/Kimwolf botnet before the March disruption. CNCERT, XLab, and the earlier JackSkid research name no operator. No independent source has measured a Dysphoria attack peak or confirmed the reported 200,000-device scale.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Dysphoria-IoT-Botnet-Evolution-A-Complex-Web-of-Blockchain-C2-and-Victim-Relays-ehn.shtml

  • https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html


  • Published: Mon Jul 27 13:33:45 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us