Dysphoria IoT Botnet Adopts Blockchain C2 and Victim Relays After JackSkid Takedown
The Dysphoria IoT botnet, tracked by CNCERT and XLab (Qi'anxin), has evolved to use blockchain-based name services and infected-device relays following a…
The Dysphoria IoT botnet, tracked by CNCERT and XLab (Qi'anxin), has evolved to use blockchain-based name services and infected-device relays following a…
JackSkid was one of four IoT botnets targeted in coordinated U.S., German, and Canadian law enforcement actions on March 19, 2026. Court…
Dysphoria is an IoT botnet tracked by CNCERT and XLab. It evolved after the JackSkid disruption to use ENS and SNS for…
Kimwolf is a related IoT botnet documented by XLab that used ENS-based C2 late last year. It shares code and strings with…
NICT independently documented the JackSkid-to-ENS/SNS shift in May 2026 and found code and strings shared with several other botnet families.
ENS is a blockchain-based name service used by Dysphoria for C2 resolution. The botnet uses ENS domains like m3rnbvs5d[.]eth and burrberry[.]eth to…
Nokia Deepfield documented the JackSkid operator's shift to ENS-based C2 after the March 2026 disruption. It provides network analytics and DDoS protection.
Comcast's threat lab documented the JackSkid operator's fallback to ENS-based C2 after the March 2026 law enforcement operation.