Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
ResearchOur summary
The Dysphoria IoT botnet has evolved by integrating blockchain-based name services like Ethereum Name Service (ENS) and Solana Name Service (SNS), along with victim-infected relays, to manage its command-and-control infrastructure. This change follows a March 2026 law enforcement operation targeting the JackSkid botnet, which previously used similar tactics. Researchers from CNCERT and XLab estimate the botnet includes over 200,000 devices globally, though these figures lack independent verification. The new architecture complicates traditional mitigation strategies by decentralizing control mechanisms. Defenders are advised to secure exposed IoT devices, update firmware, and disable unnecessary features like UPnP.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.