TechNewsReel
Live

Dysphoria Botnet Adopts Blockchain C2 After JackSkid Takedown

Security researchers trace 200,000 infected IoT devices using Ethereum and Solana name services to evade disruption.

TechNewsReel Newsroom · July 28, 2026

A Resilient Successor

The Dysphoria botnet has emerged as a technically evolved successor to JackSkid, the IoT malware network disrupted by international law enforcement in March 2026. Operators integrated code from both JackSkid and fbot variants while deploying blockchain-based command-and-control infrastructure that resists traditional takedown methods.

Researchers at China's CNCERT and QiAnXin XLab have documented approximately 200,000 infected devices worldwide, with telemetry showing a peak of 239,000 overseas connections in a single day. These figures come from researcher telemetry and have not been independently verified by third-party security firms.

Blockchain-Powered Command Infrastructure

Dysphoria's most significant innovation is its use of the Ethereum Name Service (ENS) and Solana Name Service (SNS) for C2 domain resolution. By storing command server addresses in blockchain records, operators can update infrastructure without relying on traditional DNS, rendering domain-seizure and IP-blocking strategies largely ineffective.

This decentralized approach marks a notable shift in botnet architecture. Previous networks relied on fixed domains or fast-flux DNS, both vulnerable to law enforcement intervention. Blockchain records persist across the distributed ledger, requiring coordination across multiple networks to disrupt.

Infection and Traffic Management

The botnet spreads through Telnet and SSH weak-password guessing, exploiting devices with default or easily cracked credentials. It also targets a known command-injection vulnerability in Linksys E1700 routers (CVE-2025-9528).

Once compromised, devices run a relay-only variant that uses UPnP for automatic port mapping and Linux epoll for efficient traffic management. This allows the infrastructure to maintain persistent connections while minimizing resource consumption on infected hosts.

Unverified Capability Claims

Botnet operators have advertised attack capabilities reaching up to 4 Tbps, though this claim remains unverified. No independent security firm has empirically measured Dysphoria's maximum attack volume, and specific victim names or documented attack peaks have not been publicly released.

Why This Matters

The adoption of blockchain-based C2 represents an arms-race escalation. Traditional botnet takedowns depend on seizing domains or sinkholing IP addresses—tactics that fail against decentralized name resolution. Combined with the ubiquity of poorly secured IoT devices, Dysphoria creates infrastructure capable of sustained DDoS campaigns against gaming platforms, internet services, and critical infrastructure.

Security teams should prioritize disabling unused Telnet/SSH services, enforcing strong credentials, and patching known router vulnerabilities. For network operators, UPnP should be disabled at perimeter boundaries unless explicitly required.

The botnet's evolution suggests future campaigns will increasingly adopt decentralized technologies to evade disruption, raising the bar for defensive coordination across security vendors, ISPs, and law enforcement.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.