Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Dysphoria IoT botnet has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The botnet's population is estimated to be above 200,000 bots, with 4,401 confirmed active devices insid…
Intelligence analysis by Llama

The Dysphoria botnet has evolved to use blockchain-based name services and infected-device relays, making it harder to disrupt. The botnet's population is estimated to be above 200,000 bots, with a significant presence in China and abroad.
Imagine a big network of computers that can work together to do bad things. This network is called a botnet. The Dysphoria botnet is like a big team of computers that can work together to do bad things, and it's getting harder to stop because it's using special tools to hide.
Analysis
A $60B Vote of Confidence
The Dysphoria IoT botnet has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The botnet's population is estimated to be above 200,000 bots, with 4,401 confirmed active devices inside China between July 14 and 20 and a single-day peak of 239,000 bots abroad. The researchers published no counting or de-duplication methodology, so the numbers should not be read as a precise device census.
Why Cursor?
Defenders should patch exposed IoT gear, replace devices that can no longer be updated, eliminate default and weak credentials, and disable remote management and UPnP where they are not needed. The lineage runs through JackSkid, one of four IoT botnets targeted in coordinated U.S., German, and Canadian law-enforcement actions on March 19. Court documents attributed more than 90,000 DDoS commands to JackSkid alone.
The Road Ahead
The researchers say the design makes the botnet harder to disrupt. The botnet still depends on blockchain records, reachable distribution nodes, and compromised relays. Japan's NICT independently documented the same JackSkid-to-ENS/SNS shift in May, and, like Nokia and Comcast, found code and strings shared with several other botnet families. That overlap points to shared tooling rather than proof of a single operator, and none of the researchers name one.
Key points
- The Dysphoria IoT botnet has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure.
- The botnet's population is estimated to be above 200,000 bots, with 4,401 confirmed active devices inside China between July 14 and 20 and a single-day peak of 239,000 bots abroad.
- Defenders should patch exposed IoT gear, replace devices that can no longer be updated, eliminate default and weak credentials, and disable remote management and UPnP where they are not needed.
- The botnet still depends on blockchain records, reachable distribution nodes, and compromised relays.
If the researchers can continue to track and understand the Dysphoria botnet, they may be able to develop new strategies to disrupt it and prevent it from causing harm. Additionally, the use of blockchain-based name services and infected-device relays may make it harder for the botnet to operate, potentially limiting its impact.
The Dysphoria botnet's use of blockchain-based name services and infected-device relays makes it harder to disrupt, and its large population of over 200,000 bots means it has the potential to cause significant harm. If the botnet is not addressed, it could continue to operate and cause problems for IoT devices and networks.



