← Back to Feed
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
July 27, 2026 · The Hacker News · Severity: MEDIUM
The Dysphoria IoT botnet, tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays following a March law-enforcement operation against JackSkid infrastructure. Researchers put its population above 200,000 bots, with 4,401 confirmed active devices inside China between July 14-20 and a single-day peak of 239,000 bots abroad. The botnet's design using blockchain C2 and victim relays makes it harder to disrupt than traditional IoT botnets.
Key Takeaways
- Dysphoria IoT botnet uses blockchain-based name services and infected-device relays to resist takedown.
- CNCERT and XLab estimate population above 200,000 bots with a single-day peak of 239,000 devices abroad.
- The botnet adapted after the March 2026 law-enforcement disruption of the related JackSkid infrastructure.