Dysphoria IoT Botnet Integrates Blockchain C2 and Relays to Evade Law Enforcement
Summary
The Dysphoria IoT botnet has integrated blockchain-based name services and proxy relays to improve infrastructure resilience against law enforcement operations.
Details
The Dysphoria IoT botnet (actively tracked by CNCERT and Qi'anxin's XLab) has retooled its command-and-control (C2) infrastructure to resist international law enforcement actions.
Technical Infrastructure Upgrades
The botnet has deployed: - Blockchain-based DNS and name services for C2 addressing - Infected-device proxy relays to obscure back-end infrastructure
These upgrades follow a March joint law enforcement campaign that disrupted its predecessor botnet, JackSkid.
Mapped Footprint
Global network telemetry indicates that the botnet maintains a footprint of over 200,000 active nodes, peaking at 239,000 bots abroad and 4,401 within China.
Related Pages
- Dysphoria Iot Botnet Adopts Blockchain C2 And Victim Relays After Jackskid Disru\n- Nadmesh Botnet\n\nSources: raw/digests/Cyber-Digest-2026-07-28