Dysphoria, a sophisticated Internet of Things (IoT) botnet, has evolved to utilize blockchain-based name services (ENS and SNS) and a relay-mesh architecture to evade law enforcement. Following disruptions to the JackSkid infrastructure in early 2026, the botnetโs operators shifted to decentralized command-and-control (C2) mechanisms. This design decouples the primary controllers from the bots by using infected devices as relays, making the infrastructure significantly harder to take down through traditional server seizures.
Researchers from CNCERT and XLab estimate the botnet's scale at over 200,000 devices, primarily propagating via Telnet and SSH credential guessing alongside the exploitation of known vulnerabilities like CVE-2025-9528. Despite claims of 4 Tbps DDoS capabilities, these metrics remain unverified. Security professionals are advised to patch exposed IoT gear, disable UPnP, and eliminate default credentials to mitigate the risk of infection.
Top comments (0)