Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSkid botnet operation, makes traditional server seizure methods less effective and significantly increases the botnet's operational scale, despite the lack of independent verification of device counts. The design keeps controllers one step removed from exposed addresses, complicating conventional server seizure.
The Dysphoria IoT botnet, tracked by CNCERT and XLab, has adopted a more sophisticated architecture, incorporating blockchain-based name services and victim relays to evade disruption. This evolution follows a coordinated law-enforcement operation targeting JackSkid infrastructure in March.
CNCERT and XLab estimate the botnet population to be over 200,000 devices, though these numbers haven't been independently verified. Telemetry indicates 4,401 active devices within China between July 14 and 20, with a peak of 239,000 bots abroad.
Within days of the JackSkid disruption, Dysphoria began utilizing an Ethereum Name Service (ENS) domain, m3rnbvs5d[.]eth, for command-and-control (C2). XLab’s analysis reveals that the burrberry[.]eth record encodes distribution-node IPv4 addresses, while 24carnforth2merseyside[.]sol supplies other infrastructure records. The botnet uses these records to route traffic through infected devices, keeping controllers one step removed from exposed addresses.
The Dysphoria architecture has undergone several rapid iterations, including the adoption of Solana Name Service (SNS) in early May and a relay-only variant in June, with UPnP-based port mapping added to traverse NAT gateways. The relay-only build drops the DDoS modules and instead uses UPnP to map ports on the local gateway and Linux epoll to shuttle traffic between an outside connection and a remote C2 service.
Japan's NICT independently documented the same JackSkid-to-ENS/SNS shift in May. XLab and CNCERT note that Dysphoria attacks internet-service and gaming targets almost daily, but they do not name any victims or measured attack peaks. The botnet advertises attacks of up to about 4 Tbps for tens to hundreds of dollars, but this is an operator claim, not a measured attack.
Dysphoria spreads primarily through weak Telnet and SSH credentials and known remote-code-execution flaws in routers, gateways, and cameras, with CVE-2025-9528 (a Linksys E1700 command injection flaw) being a notable example. The vendor did not respond to the original report, and NVD rates the flaw as requiring high privileges, with neither publication explaining how it fits the botnet's propagation chain. Despite differing vulnerability lists, XLab and CNCERT agree that weak credentials remain the most consistent entry point.
Cloudflare measured a 31.4 Tbps attack from the related AISURU/Kimwolf botnet before the March disruption. No independent source has measured a Dysphoria attack peak or confirmed the reported 200,000-device scale. The botnet’s complex design makes traditional server seizure methods less effective.
