type: incident ยท created: 2026-07-27 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
Dysphoria IoT Botnet Adopts Blockchain C2 and Victim Relays After JackSkid Disruption
Summary
The Dysphoria IoT botnet lineage, tracked by China's CNCERT and Qi'anxin's XLab, has evolved to use blockchain-based name services and infected-device relays for command-and-control following the March 2026 law enforcement operation against JackSkid infrastructure.
Key Details
| Field | Detail |
|---|---|
| Botnet | Dysphoria (lineage) |
| Estimated population | 200,000+ devices |
| Confirmed active (China, Jul 14โ20) | 4,401 |
| Single-day peak (abroad) | 239,000 |
| C2 mechanism | Blockchain-based name services |
| Relay mechanism | Infected-device relays |
| Precipitating event | JackSkid infrastructure takedown (March 2026) |
| Tracked by | CNCERT, Qi'anxin XLab |
Evolution
Following the March 2026 law enforcement disruption of JackSkid infrastructure, the Dysphoria botnet operators pivoted to more resilient command-and-control architectures:
- Blockchain-based C2 โ Using blockchain name services for infrastructure resolution, making takedowns significantly harder
- Victim-device relays โ Leveraging compromised devices as relay nodes, reducing reliance on centralised infrastructure
Caveats
No independent counting methodology has been published for the 200,000+ and 239,000 figures. Numbers should be treated as researcher estimates.
Mitigation
- Patch exposed IoT devices
- Eliminate default credentials
- Segment IoT networks from critical infrastructure