CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Dysphoria IoT Botnet Adopts Blockchain C2 and Victim Relays After JackSkid Takedown

July 27, 2026

The Dysphoria IoT botnet, tracked by CNCERT and XLab (Qi’anxin), has evolved to use blockchain-based name services and infected-device relays following a March 2026 law enforcement operation against the related JackSkid botnet. Researchers estimate the botnet’s population exceeds 200,000 devices, with 4,401 active devices observed inside China between July 14-20 and a single-day peak of 239,000 bots abroad. However, these numbers lack independent verification and detailed methodology.

The botnet’s lineage traces back to JackSkid, one of four IoT botnets targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026. Court documents attribute over 90,000 DDoS commands to JackSkid. Within days, Nokia Deepfield and Comcast’s threat lab observed the operator shifting to an Ethereum Name Service (ENS) domain (m3rnbvs5d[.]eth) for command-and-control (C2). XLab’s timeline begins with a JackSkid sample captured on March 25 that resolves C2 through the same ENS domain.

Dysphoria now uses ENS and Solana Name Service (SNS) records to encode distribution-node IPv4 addresses and other infrastructure. The DDoS sample requests a current server list from a distribution node over HTTP, with listed endpoints being infected machines relaying traffic to real controllers. This design keeps controllers one step removed from exposed addresses. A relay-only variant appeared on June 25, using UPnP for port mapping and Linux epoll to shuttle traffic, dropping DDoS modules entirely.

The botnet spreads via Telnet and SSH weak-password guessing and known IoT remote-code-execution flaws, including CVE-2025-9528 (Linksys E1700 command injection). XLab reports Dysphoria attacks internet-service and gaming targets almost daily, with a storefront advertising attacks up to ~4 Tbps for tens to hundreds of dollars. However, no independent source has confirmed attack peaks or the reported device scale.

CVEs: CVE-2025-9528, CVE-2026-50522

Attack groups: JackSkid

Malware: Dysphoria, Kimwolf, AISURU

Companies: CNCERT, XLab, Qi'anxin, Nokia Deepfield, Comcast, NICT, Linksys

Products: Ethereum Name Service, Solana Name Service, UPnP, Linux epoll

Events: JackSkid disruption March 2026