Dysphoria IoT Botnet Uses Blockchain Name Services To Strengthen Command And Control

Published:

Cybersecurity researchers have reported that the Dysphoria Internet of Things (IoT) botnet has significantly evolved its infrastructure by adopting blockchain based name services and infected device relays for command and control communications. According to joint research by CNCERT, China’s national computer emergency response team, and XLab, the threat intelligence laboratory of Qi’anxin, the changes were introduced after an international law enforcement operation disrupted the infrastructure of the JackSkid IoT botnet in March 2026. Researchers believe these modifications make Dysphoria more resistant to traditional disruption efforts by reducing its dependence on centralized command and control servers. While the researchers estimate that the botnet has infected more than 200,000 devices globally, they also acknowledged that the reported figures have not been independently verified because no methodology for counting or eliminating duplicate devices has been published. During the period between July 14 and July 20, researchers observed 4,401 confirmed active devices within China and a reported peak of approximately 239,000 active bots outside the country on a single day.

The investigation traced the botnet’s development back to JackSkid, one of four IoT botnets targeted in coordinated law enforcement operations conducted by authorities in the United States, Germany, and Canada on March 19. Court documents linked JackSkid to more than 90,000 distributed denial of service commands before the disruption. Within days of the operation, security researchers from Nokia Deepfield and Comcast observed the operators switching to an Ethereum Name Service domain known as m3rnbvs5d.eth for command and control communication. XLab later identified a JackSkid sample captured on March 25 that relied on the same blockchain domain for resolving command infrastructure. According to the research, the Dysphoria botnet now stores distribution node addresses using Ethereum Name Service while additional infrastructure records are provided through Solana Name Service. Rather than connecting directly to command servers, infected devices obtain updated server lists from distribution nodes and communicate through compromised relay systems, creating an additional layer that conceals the actual command infrastructure from security researchers and law enforcement agencies.

Researchers documented a rapid evolution of the malware throughout recent months. By the end of April, Dysphoria incorporated custom RC4 string encryption together with Ethereum Name Service resolution. Early May introduced support for Solana Name Service, while a relay focused version emerged on June 25. Days later, the malware added Universal Plug and Play based port mapping to bypass network address translation gateways. Unlike earlier versions that included distributed denial of service modules, the relay only variant focuses on forwarding communications between infected devices and remote command infrastructure using Linux epoll and automatic port mapping techniques. XLab noted similarities between Dysphoria and the previously documented Kimwolf botnet, which also relied on blockchain based command resolution. However, researchers emphasized that shared code and infrastructure patterns suggest common development tools rather than confirming that both botnets are operated by the same threat actor. Security researchers also observed that the botnet still depends on blockchain records, distribution nodes, and compromised relay devices, meaning its infrastructure remains vulnerable to targeted disruption despite becoming more resilient.

According to CNCERT and XLab, Dysphoria primarily spreads by exploiting weak Telnet and SSH credentials while also targeting known remote code execution vulnerabilities affecting routers, gateways, and internet connected cameras. One of the vulnerabilities referenced in the published research is CVE 2025 9528, a command injection flaw affecting the Linksys E1700 router that was publicly disclosed together with an exploit during 2025. Researchers noted, however, that neither publication fully explains how the vulnerability contributes to the botnet’s propagation process, and the National Vulnerability Database classifies the flaw as requiring high privileges. Additional analysis comparing the research publications also found differences in the vulnerability lists despite both reports describing the same joint investigation. XLab stated that Dysphoria launches attacks against internet service providers and gaming related targets on an almost daily basis, although no specific victims or independently verified attack volumes were disclosed. Researchers advised organizations to reduce their exposure by applying security updates to internet connected devices, replacing unsupported hardware, eliminating default and weak passwords, and disabling remote management services and Universal Plug and Play wherever those features are not required.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Related articles

spot_img