The Dysphoria botnet, a notorious network affecting Internet of Things (IoT) devices, has incorporated blockchain-based systems to enhance its resilience against disruptions. Following a coordinated law enforcement action in March targeting the infrastructure of the JackSkid botnet, Dysphoria has adopted blockchain name services and infected-device relays. This strategic move aims to fortify the botnet against future interventions, according to research from CNCERT and XLab.
Background and Current Landscape
China’s national computer emergency response team, CNCERT, along with Qi’anxin’s XLab, estimate that Dysphoria has amassed over 200,000 bots. During a monitoring period between July 14 and 20, they identified 4,401 active devices within China and noted a peak of 239,000 bots internationally in a single day. However, these figures have not been independently verified, and the methodologies used for these counts remain undisclosed.
Security experts advise that IoT devices should be updated regularly. Devices that can no longer receive updates should be replaced, and default or weak passwords must be avoided. Additionally, disabling unnecessary remote management and UPnP can help mitigate the risk of botnet infections.
Technical Evolution and Strategy
The Dysphoria botnet traces its origins to JackSkid, a botnet disrupted in March through international law enforcement efforts. Shortly after, its operators transitioned to using the Ethereum Name Service (ENS) domain for command-and-control (C2) tasks. XLab’s research highlights how Dysphoria has evolved since then, adopting new techniques such as Solana Name Service (SNS) resolution and implementing relay-only variants to obscure its operations.
These technical advancements, including the use of UPnP for port mapping and Linux epoll for traffic management, present significant challenges for those attempting to dismantle the botnet. By utilizing blockchain records and compromised relays, Dysphoria maintains a robust and elusive network infrastructure.
Propagation and Impact
Independent research corroborates the shift in Dysphoria’s operational approach, linking it to similar tactics observed in other botnet families. However, this does not conclusively point to a single entity behind these operations. CNCERT and XLab identify Telnet and SSH weak-password guessing, along with known IoT vulnerabilities such as the Linksys E1700 command-injection flaw (CVE-2025-9528), as primary vectors for Dysphoria’s spread.
Despite its aggressive expansion, Dysphoria’s exact impact remains unclear. While the botnet targets various sectors, including internet services and gaming, specific victims and attack intensities have not been documented. Claims of attack capabilities reaching up to 4 Tbps are based on operator assertions rather than empirical data. Notably, Cloudflare measured a 31.4 Tbps attack linked to a related botnet prior to March’s crackdown.
The ongoing development and sophistication of the Dysphoria botnet underscore the evolving nature of cybersecurity threats. As it continues to adapt and grow, understanding and mitigating its spread remains a critical challenge for cybersecurity professionals worldwide.
