Dysphoria IoT botnet uses blockchain domains to hide 200k bots

https://iottechnews.com/wp-content/uploads/2026/07/dysphoria-IoT-botnet-blockchain-domains-bots-malware-cyber-security-infosec-ddos-c2.jpg

IoT botnet Dysphoria has infected over 200,000 devices, hiding command servers on Ethereum and Solana blockchain domains. The botnet family first appeared in the wild in March 2026, and X Lab, the research arm of QAX, has tracked its development since.

X Lab published its findings jointly with the National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT). Researchers describe a network built on Linux-based IoT malware code lineages known as jackskid and fbot, which Dysphoria’s authors have reworked repeatedly over months rather than years.

How blockchain domains replace command servers

Most botnets rely on hardcoded IP addresses or domain names for command-and-control (C2), giving defenders a fixed target to seize or sinkhole. Dysphoria queries Ethereum Name Service (ENS) and Solana Name Service (SNS) domains instead, pulling C2 infrastructure details out of TXT records rather than conventional DNS.

The ENS domain burrberry.eth returns relay distribution node addresses...

Copyright of this story solely belongs to iottechnews.com. To see the full text click HERE

Read more