Research ddos-botnet ics-ot-iot
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
CVE Tools coverage
The Dysphoria IoT botnet has evolved by integrating blockchain-based name services like Ethereum Name Service (ENS) and Solana Name Service (SNS), along with victim-infected relays, to manage its command-and-control infrastructure. This change follows a March 2026 law enforcement operation targeting the JackSkid botnet, which previously used similar tactics. Researchers from CNCERT and XLab estimate the botnet includes over 200,000 devices globally, though these figures lack independent verification. The new architecture complicates traditional mitigation strategies by decentralizing control mechanisms. Defenders are advised to secure exposed IoT devices, update firmware, and disable unnecessary features like UPnP.