Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-28 ยท updated: 2026-07-28 ยท tags: [incident, c2] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false

Dysphoria IoT Botnet Integrates Blockchain C2 and Relays to Evade Law Enforcement

Summary

The Dysphoria IoT botnet has integrated blockchain-based name services and proxy relays to improve infrastructure resilience against law enforcement operations.

Details

The Dysphoria IoT botnet (actively tracked by CNCERT and Qi'anxin's XLab) has retooled its command-and-control (C2) infrastructure to resist international law enforcement actions.

Technical Infrastructure Upgrades

The botnet has deployed: - Blockchain-based DNS and name services for C2 addressing - Infected-device proxy relays to obscure back-end infrastructure

These upgrades follow a March joint law enforcement campaign that disrupted its predecessor botnet, JackSkid.

Mapped Footprint

Global network telemetry indicates that the botnet maintains a footprint of over 200,000 active nodes, peaking at 239,000 bots abroad and 4,401 within China.

Related Pages