Dysphoria IoT Botnet Integrates Blockchain-Based C2 and Victim Relays Post-JackSkid Disruption
The Dysphoria IoT botnet has adopted blockchain-based command-and-control (C2) infrastructure and victim relays following the disruption of JackSkid, making it harder to dismantle. It leverages weak credentials and known vulnerabilities like CVE-2025-9528 to propagate, with researchers noting its shift to Ethereum and Solana Name Services for resilience.
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt.
CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence lab of Chinese
*** END OF TRANSMISSION ***