Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

bleepingcomputer+1cybersecuritydive+1cybersecuritynews+1A fast-evolving IoT botnet called Dysphoria has infected an estimated 200,000 devices worldwide, using blockchain-based domain systems to hide its command-and-control infrastructure from law enforcement and security researchers, according to findings published by QiAnXin XLab on July 27.bleepingcomputer+1
The botnet emerged in late March, shortly after a multinational law enforcement operation led by the U.S., Canada and Germany dismantled four major IoT botnets — including JackSkid, from which Dysphoria descends. That March operation, announced by the Justice Department, seized servers, domains and other systems powering the Aisuru, KimWolf, JackSkid and Mossad botnets, which had collectively infected more than three million devices.cybersecuritydive
Rather than relying on traditional domain names that authorities can seize, Dysphoria's operators programmed the malware to look up Ethereum Name Service and Solana Name Service records to locate active control servers. The technique stores infrastructure information on blockchain networks, where records cannot be removed by court order or registrar cooperation the way conventional domains can.interisle.substack+2
XLab researchers found that C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm. The design creates what analysts describe as a layered resolution chain: infected devices query blockchain domains to find relay-distribution nodes, which then provide the addresses used for direct command-and-control communication.cybersecuritynews+1
Since XLab first spotted Dysphoria on March 25, the botnet has undergone frequent code updates, adding multi-chain support, new domains, and a variant discovered in late June that strips out DDoS functionality entirely and instead converts compromised devices into network relay proxies. That variant abuses UPnP to create 155 port-forwarding rules on infected devices, exposing internal services to inbound internet connections.bleepingcomputer+1
The botnet spreads through weak Telnet and SSH credentials and exploits vulnerabilities in routers, cameras and other IoT hardware, including flaws dating back to 2017. Between July 14 and 20, XLab recorded a peak of 740,000 daily pings from infected hosts, with 239,000 connections from overseas clients. The operators claim a maximum DDoS capacity of 4 Tbps on a clearnet site that markets the service as a stress-testing tool.cybersecuritynews+1
The combination of blockchain-based naming, encrypted configurations, and a distributed relay mesh composed of victim devices makes Dysphoria harder to disrupt through the seizure-and-sinkhole playbook that proved effective against JackSkid just months earlier. "In just a few months, the family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience," XLab said in its report.mallory+2