DEV Community

Mark0
Mark0

Posted on

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Dysphoria, a sophisticated Internet of Things (IoT) botnet, has evolved to utilize blockchain-based name services (ENS and SNS) and a relay-mesh architecture to evade law enforcement. Following disruptions to the JackSkid infrastructure in early 2026, the botnetโ€™s operators shifted to decentralized command-and-control (C2) mechanisms. This design decouples the primary controllers from the bots by using infected devices as relays, making the infrastructure significantly harder to take down through traditional server seizures.

Researchers from CNCERT and XLab estimate the botnet's scale at over 200,000 devices, primarily propagating via Telnet and SSH credential guessing alongside the exploitation of known vulnerabilities like CVE-2025-9528. Despite claims of 4 Tbps DDoS capabilities, these metrics remain unverified. Security professionals are advised to patch exposed IoT gear, disable UPnP, and eliminate default credentials to mitigate the risk of infection.


Read Full Article

Top comments (0)