IoT Botnet Dysphoria Turns to Blockchain and Hijacked Devices to Dodge Takedown

Dysphoria IoT botnet scaled to over 200,000 devices by weaponizing blockchain name services and turning victims into C2 relays after JackSkid's disruption. XLab and CNCERT detail its modified RC4 encryption, ENS/SNS resolution tricks, and daily DDoS rentals. Basic patching still cuts infections. (48 words)
IoT Botnet Dysphoria Turns to Blockchain and Hijacked Devices to Dodge Takedown
Written by Emma Rogers

Security teams thought they had seen every trick in the book for keeping botnets alive. Then came Dysphoria.

This Internet of Things operation emerged in the first months of 2026. It quickly scaled to claims of more than 200,000 compromised devices. Chinese researchers at Qi’anxin XLab and CNCERT tracked its every move. Their findings paint a picture of rapid adaptation that outpaces traditional defenses. XLab’s technical report details how the botnet morphed from a Mirai descendant into something far harder to kill.

Its story begins with JackSkid. Law enforcement from the United States, Germany and Canada hit that network on March 19. Court records tied it to more than 90,000 DDoS commands. The operation took down fast-flux domains and dropper servers. Operators lost their primary command infrastructure overnight. But they did not disappear.

Within days the remnants pivoted. Builds surfaced that resolved command-and-control addresses through Ethereum Name Service records. Comcast’s reverse-engineering team documented the shift in a detailed March analysis. “The operator’s fallback to ENS-based resolution provides some continuity,” they noted. That same m3rnbvs5d.eth domain would anchor Dysphoria’s early operations. Comcast’s JackSkid report laid out the technical lineage before publication was delayed for the disruption.

Dysphoria took the idea and ran. By late April samples carried upgraded string encryption. A heavily modified RC4 algorithm protected configuration data. The process starts with standard key-scheduling. Then five rounds of linear congruential generation shuffle the S-box. The pseudo-random generation stage adds linear feedback shift register steps, triple swaps and rotate-XOR operations. The 16-byte key remains constant across variants: 08 45 3C D1 F9 5D 5C 27 61 21 1C BD E3 0F 3B 9C.

But encryption was only part of the story. Command resolution moved to the blockchain. Three domains handle different roles. burrberry.eth stores relay node addresses under a “node” key. ukranianhorseriding.eth maps basic network infrastructure via a “network” record. The Solana Name Service equivalent, 24carnforth2merseyside.sol, uses a “deserialized” field. Devices query these public ledgers. They receive data formatted as fake IPv6 addresses. A custom decode routine with key 0x80408454 extracts real IPv4 targets. The function applies nibble swaps, rotates and key-derived XOR-add operations. No central server. No domain registrars to pressure. Just immutable ledger entries anyone can read but few can alter.

And then the relays appeared.

By late June a distinct sample variant dropped all attack code. Hash b0782a9d6eef2ce02f734a6e5e1d8e0f9a2b65be marks this pure proxy build. Infected devices turn into transparent relays. They bind 155 ports. UPnP requests punch holes through consumer routers. Epoll handles bidirectional non-blocking forwarding between external attackers and final command servers. Every four seconds the relay phones home with JSON status. Connection counts. Bandwidth estimates. All sent to heartbeat domains that themselves float across the mesh.

Distribution nodes sit one layer above. DDoS-capable bots query burrberry.eth. They receive a list of these relays. An HTTP GET to port 9000 with parameter key=meowmeowmeow returns fresh C2 addresses. Those addresses often point back to other compromised devices. The botnet eats its own infected population to hide its true infrastructure. XLab researchers mapped the flow. Their telemetry showed active C2 addresses trending alongside relay counts. The hybrid design separates attack muscle from communication backbone.

Infection tactics stayed classic. Yet they proved sufficient. Weak Telnet and SSH passwords open most doors. A long list of known vulnerabilities provides backup. Researchers listed more than a dozen. Older flaws like CVE-2017-17215 sit alongside 2025 issues targeting Linksys routers and various cameras. Default credentials still work on too many devices. Operators scan continuously. Successful logins trigger downloads from FTP servers sporting the banner “220 cool ftp server hosted on brian krebs’ giant ass 4head.” The taunt leaves little doubt about attitude.

Scale materialized fast. Between July 14 and 20 XLab and CNCERT counted 4,401 active bots inside China. Daily new infections peaked at 1,801 there. Global figures reached 239,000 in a single day. Control panel screenshots suggested a steady 200,000 bots available for rent. These numbers come from one national lab and have not been independently verified. Still, the activity patterns match. The Hacker News covered the disclosure hours after the XLab report appeared on July 25.

Daily DDoS campaigns target internet service providers and online gaming platforms. Pricing runs from tens to hundreds of dollars depending on duration and power. Operators advertise peaks near 4 terabits per second. Independent measurements of similar Mirai descendants have exceeded 30 terabits. Cloudflare documented one 31.4 Tbps event from a related family. The commercial model looks mature. Rental panels accept cryptocurrency. Customers pick targets and watch graphs.

Shared code and tooling suggest the operation may not stand alone. Strings and algorithms overlap with other active botnets. Some researchers suspect multiple groups pull from the same kit. Others point to a single sophisticated actor iterating quickly. The June 25 introduction of the dedicated relay build marks a clear architectural leap. Functional separation protects the attack fleet while relays absorb takedown pressure.

Defenders face a moving target. Traditional domain blocks fail against ENS and SNS lookups. IP blacklists struggle when C2 lives on victim devices that rotate hourly. Disrupting one relay barely dents the mesh. Yet basic hygiene still works. Patch every exposed IoT device. Replace those that cannot receive updates. Kill default passwords. Turn off UPnP and remote management interfaces unless required. These steps cut the recruitment pipeline.

The broader trend worries analysts. Blockchain C2 first appeared in research papers years ago. Now it reaches commodity botnets. Aeternum offered a Polygon-based panel for $200. North Korean actors experimented with transaction calldata dead-drops. Each implementation lowers the bar. Dysphoria combines the technique with victim-powered relays. The result feels like a logical endpoint for resilient IoT crime.

Monitoring must evolve. Security teams need to watch blockchain transactions for suspicious records. They should scan for unusual UPnP mapping patterns on home routers. Behavioral detection on IoT endpoints becomes essential. Signature-based tools alone will miss these samples. The modified RC4 alone defeats simple string scans.

So far law enforcement has stayed quiet on Dysphoria. The March action against JackSkid and peers showed coordination works. But new infrastructure resists the same playbook. Blockchain entries cannot be seized like servers. Relays regenerate from fresh infections. The operator simply updates a few smart contract fields and keeps going.

Industry insiders expect more experiments. Solana’s speed and low fees make it attractive. Ethereum’s established name service offers familiarity. Hybrid designs that blend both will likely spread. At the same time, botnet authors watch how defenders respond. Any successful mitigation against Dysphoria will shape the next iteration.

For now the network hums. Thousands of compromised routers, cameras and smart appliances forward traffic, launch volumetric attacks and report status. Their owners notice nothing. Bandwidth bills tick up slightly. CPU runs a little warmer. The botnet stays quiet until needed. Then it strikes with force that traditional defenses struggle to absorb.

The message for operators of critical infrastructure is clear. Assume your edge devices are already compromised. Verify every connection. Monitor outbound blockchain queries from Linux endpoints that should never touch cryptocurrency networks. And above all, reduce the attack surface before the next variant adds another layer of evasion.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us