China's national computer emergency response team (CNCERT) and threat‑intelligence lab XLab report that the Dysphoria IoT botnet has switched to blockchain‑based name services and victim relays, making disruption significantly harder. The shift follows a March law‑enforcement operation targeting the JackSkid infrastructure.
Key Takeaways
- Dysphoria now uses blockchain‑based command‑and‑control (C2)
- Compromised devices act as relays, expanding the botnet
- Design change followed the JackSkid takedown, increasing resilience
Dysphoria is a widely tracked Internet‑of‑Things (IoT) botnet monitored by China’s CNCERT and XLab. Recent findings reveal that the botnet has integrated blockchain‑based name services (similar to ENS) into its C2 infrastructure, effectively bypassing traditional domain‑based control servers.
In addition, Dysphoria now leverages infected devices as relay nodes. This multi‑layer relay architecture obscures traffic patterns and makes it considerably tougher for defenders to trace or shut down the entire network.
Why This Matters
BozokMedia analysis shows that adopting blockchain for C2 gives cyber‑criminals a stealthier command channel, rendering conventional takedown methods less effective. The move highlights a growing trend of leveraging decentralized technologies for malicious purposes.
"Using blockchain as a C2 backbone introduces a new layer of complexity for defenders," says cyber‑security researcher Dr. Anil Sharma.
Frequently Asked Questions
What types of IoT devices does the Dysphoria botnet target?
Primarily weak‑password routers, IP cameras, and smart hubs.
How can organizations mitigate blockchain‑based C2 threats?
Deploy advanced network traffic analytics and participate in threat‑intel sharing platforms that monitor blockchain activity.