- The Dysphoria IoT botnet, tracked by CNCERT and XLab, now uses Ethereum Name Service (ENS) and Solana Name Service (SNS) for resilient command-and-control, making take-downs harder.
- Researchers estimate over 200,000 infected devices, though the counting methodology has not been independently verified, and no single attack peak has been confirmed.
- The botnet evolved from the JackSkid family, which was disrupted by law enforcement in March 2026, and now relies on a relay mesh of compromised devices to shield its controllers.
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt.
CNCERT, China’s national computer emergency response team, and XLab, the threat-intelligence lab of Chinese firm Qi’anxin, put its population above 200,000 bots. However, none of the counts have been independently reproduced, and the researchers published no counting or de-duplication methodology.
The lineage runs through JackSkid, one of four IoT botnets targeted in coordinated U.S., German, and Canadian law-enforcement actions on March 19. Within days, Nokia Deepfield and Comcast’s threat lab documented the operator falling back to an ENS domain, m3rnbvs5d[.]eth, for command-and-control.
Consequently, XLab found that the burrberry[.]eth record encodes distribution-node IPv4 addresses, while 24carnforth2merseyside[.]sol supplies other infrastructure records. The DDoS sample asks a distribution node over HTTP for a current server list, and the listed endpoints are infected machines relaying traffic to the real controllers.
The XLab analysis, published July 25, tracks a fast run of builds: custom RC4 string encryption and ENS resolution at the end of April, followed by Solana Name Service (SNS) resolution in early May. Meanwhile, Japan’s NICT independently documented the same JackSkid-to-ENS/SNS shift in May, finding code and strings shared with several other botnet families.
XLab and CNCERT say Dysphoria spreads through Telnet and SSH weak-password guessing and a set of known IoT remote-code-execution flaws, such as CVE-2025-9528 in Linksys E1700 routers. The shift to blockchain records complicates conventional server seizure, but the botnet still depends on reachable distribution nodes and compromised relays.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
