Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-27 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Dysphoria IoT Botnet Adopts Blockchain C2 and Victim Relays After JackSkid Disruption

Summary

The Dysphoria IoT botnet lineage, tracked by China's CNCERT and Qi'anxin's XLab, has evolved to use blockchain-based name services and infected-device relays for command-and-control following the March 2026 law enforcement operation against JackSkid infrastructure.

Key Details

Field Detail
Botnet Dysphoria (lineage)
Estimated population 200,000+ devices
Confirmed active (China, Jul 14โ€“20) 4,401
Single-day peak (abroad) 239,000
C2 mechanism Blockchain-based name services
Relay mechanism Infected-device relays
Precipitating event JackSkid infrastructure takedown (March 2026)
Tracked by CNCERT, Qi'anxin XLab

Evolution

Following the March 2026 law enforcement disruption of JackSkid infrastructure, the Dysphoria botnet operators pivoted to more resilient command-and-control architectures:

  1. Blockchain-based C2 โ€” Using blockchain name services for infrastructure resolution, making takedowns significantly harder
  2. Victim-device relays โ€” Leveraging compromised devices as relay nodes, reducing reliance on centralised infrastructure

Caveats

No independent counting methodology has been published for the 200,000+ and 239,000 figures. Numbers should be treated as researcher estimates.

Mitigation

  • Patch exposed IoT devices
  • Eliminate default credentials
  • Segment IoT networks from critical infrastructure

References