Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria is an IoT botnet line that evolved after the March takedown of JackSkid infrastructure, using blockchain-based name services and infected-device relays to make disruption more difficult. Researchers from CNCERT, XLab, Nokia Deepfield, Comcast, and NICT linked its spread to weak Telnet/SSH credentials and IoT flaws, but said the reported bot counts and attack scale have not been independently verified. #Dysphoria #JackSkid #CNCERT #XLab #ENS #SNS #LinksysE1700 #AISURU #Kimwolf

Keypoints

  • Dysphoria emerged after the March operation against JackSkid infrastructure.
  • The botnet uses Ethereum Name Service and Solana Name Service records for C2 resilience.
  • Infected devices now relay traffic to keep controllers hidden behind a distribution layer.
  • Researchers observed spread through weak Telnet and SSH credentials and IoT RCE flaws.
  • Reported bot counts and attack capacity were not independently confirmed.

Read More: https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html