HackMyIP
← Back to News
2026-07-27 The Hacker News

Dysphoria IoT Botnet Adopts Blockchain C2 After JackSkid Takedown

MalwareThreat Intel

Dysphoria, an Internet of Things botnet tracked by China's CNCERT and Qi'anxin's XLab threat-intelligence team, has retooled its command-and-control (C2) layer with blockchain naming services and a mesh of infected-device relays following the March takedown of the JackSkid infrastructure. Researchers estimate the botnet population at more than 200,000 bots, with telemetry recording 4,401 confirmed active devices inside China between July 14 and 20 and a single-day peak of 239,000 bots abroad, though no counting methodology has been published and the figures have not been independently reproduced. The shift, first documented after the coordinated U.S.–German–Canadian disruption of JackSkid on March 19, has since been corroborated by Japan's NICT, Nokia Deepfield, and Comcast's threat lab.

The redesign couples Ethereum Name Service (ENS) and Solana Name Service (SNS) resolution with a relay architecture that hides the true controllers behind layers of compromised machines. A sample captured six days after the JackSkid action resolves C2 through the ENS domain m3rnbvs5d[.]eth, while related records at burrberry[.]eth encode distribution-node IPv4 addresses and 24carnforth2merseyside[.]sol supplies additional infrastructure entries. Bots fetch the active server list over HTTP from those distribution nodes, then push traffic through infected relays that bridge outside connections to the real controllers using Linux epoll and UPnP-mapped ports to traverse NAT gateways. The June 25 "relay-only" build drops DDoS modules entirely and focuses on transit, a design pattern XLab previously observed in the Kimwolf botnet's ENS-based C2.

The blockchain layer complicates conventional server seizures because disruption now requires coordination with name-service registrars rather than a single hosting provider, yet it does not remove infrastructure dependencies: the botnet still relies on reachable distribution nodes, resolvable blockchain records, and a fleet of compromised relays. Defenders should patch exposed IoT firmware, replace unmaintainable hardware, audit default and weak credentials, and disable remote management and UPnP where they are not needed. A DNS leak test can help spot misconfigured edge devices leaking resolution queries to external servers, a port scanner will surface any UPnP-exposed services on the local network, and a password checker can confirm that factory defaults have been replaced with strong, unique credentials on every IoT endpoint.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

IP Lookup →IP Blacklist Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a DDoS attack? →What is a proxy server? →Is my IP blacklisted? →