Dysphoria IoT Botnet Evolves with Blockchain C2 Tactics
The Dysphoria botnet is leveraging blockchain-based naming services and device relays to evade takedown efforts. This evolution follows disruption of related JackSkid infrastructure.
TL;DR
- Dysphoria IoT botnet now uses blockchain for command-and-control (C2) communication.
- Infected devices act as relays, increasing resilience against disruption.
- Evolves after March law enforcement action against JackSkid infrastructure.
- Tracked by CNCERT and XLab threat intelligence teams.
- New architecture complicates traditional mitigation strategies.
The Dysphoria IoT botnet has introduced new evasion techniques that make it more resilient to disruption. Following a law enforcement operation in March targeting related JackSkid infrastructure, researchers from CNCERT and XLab have observed the botnet adopting blockchain-based name services and using compromised devices as communication relays.
This shift marks a significant evolution in the botnet’s architecture, moving away from centralized command structures that are easier for security teams to dismantle. By embedding its operations within decentralized systems, Dysphoria presents fresh challenges for defenders aiming to neutralize large-scale IoT threats.
Blockchain Integration Enhances Resilience
- Dysphoria now leverages blockchain-based naming services for C2 communications.
- This method avoids reliance on traditional DNS infrastructures which can be easily blocked or seized.
- Use of decentralized systems complicates tracking and attribution efforts.
Device-Based Relay Network
- Compromised IoT devices are being used as relay nodes to obscure traffic paths.
- Relay-based architectures reduce exposure of core C2 servers.
- Makes it harder for defenders to trace infections back to original command sources.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.