By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Dysphoria IoT Botnet Adopts Blockchain After JackSkid Takedown

The Dysphoria Internet of Things (IoT) botnet has evolved its operational infrastructure to incorporate blockchain-based name services and infected-device relays, a strategic adaptation following a law enforcement operation in March that targeted the JackSkid botnet's infrastructure. This move significantly enhances the botnet's resilience against disruption, making it more challenging for security researchers and authorities to track and dismantle. CNCERT, China's national computer emergency response team, and XLab, the threat intelligence lab of Chinese cybersecurity firm Knownsec, have been monitoring these developments and attribute the botnet's new design to its increased sophistication and evasion capabilities.
Previously, the JackSkid botnet, which shared similarities with Dysphoria, relied on traditional domain name system (DNS) infrastructure for its command and control (C2) communications. The March operation successfully disrupted this infrastructure, highlighting a common vulnerability in botnets that depend on centralized or easily identifiable C2 servers. In response, Dysphoria has shifted to utilizing blockchain name services, such as the Ethereum Name Service (ENS) or similar decentralized naming protocols. These services provide a more robust and censorship-resistant alternative to traditional DNS, as they are managed on a distributed ledger, making them harder to take offline or control.
Furthermore, Dysphoria has begun employing infected IoT devices as relays for its C2 traffic and for exfiltrating data from new victims. This technique, often referred to as peer-to-peer (P2P) communication within a botnet, obscures the true origin and destination of malicious traffic. By routing commands and stolen data through a network of compromised devices, the botnet creates a more decentralized and obfuscated communication channel. This makes it significantly harder to pinpoint the botnet's master controllers and to block its communications effectively. The use of victim devices as relays also adds an extra layer of complexity, as traffic appears to originate from legitimate, albeit compromised, devices.
The integration of blockchain technology and the use of infected devices as relays represent a significant advancement in the operational security of the Dysphoria botnet. These techniques are designed to circumvent the disruption methods that have proven effective against older, less sophisticated botnets. The researchers from CNCERT and XLab emphasize that this evolution underscores the ongoing cat-and-mouse game between cybersecurity defenders and malicious actors, with botnets continuously adopting new technologies to enhance their persistence and evade detection. The implications of this shift are substantial for IoT security, as it suggests a growing trend towards more resilient and decentralized botnet architectures that are harder to combat.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.