At a glance: Dysphoria replaces centralized C2 infrastructure with blockchain name services and device relays, reducing the effectiveness of law enforcement disruptions.
Following a law enforcement action against JackSkid infrastructure in March, the Dysphoria IoT botnet has transitioned its command structure to blockchain-based name services and infected devices as relays. This significantly increases resilience against disruption operations.
The Dysphoria botnet, monitored by CNCERT (China’s National Computer Emergency Response Team) and XLab (the threat intelligence lab of Chinese security company Qihoo), has decentralized its command chain. Instead of centralized Command-and-Control servers, the network now uses blockchain-based name services for coordination. Additionally, infected IoT devices themselves serve as relays for commands, breaking the dependency on individual critical infrastructure nodes.
The move followed a law enforcement action against JackSkid infrastructure in March, which previously served as a central botnet management system. Through blockchain integration and the relay system, it becomes significantly more difficult to disrupt communication pathways or identify bot operators – traditional disruption approaches such as C2 server takedowns are losing their effectiveness.
From an incident response and threat intelligence perspective, this is a sign that botnet operators are systematically increasing their resilience against state intervention. CISOs should enhance monitoring for anomalous blockchain transactions and P2P communication patterns in IoT environments and review segmentation of IoT devices to prevent lateral spread.
Source: thehackernews.com · Published 27 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.