hacker-news · Crawled Jul 27, 2026

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

3 IoCs 1 Malware
Read original article ↗

AI Summary

The Dysphoria IoT botnet, evolving from the disrupted JackSkid infrastructure, has adopted blockchain-based command-and-control (C2) mechanisms using Ethereum Name Service (ENS) and Solana Name Service (SNS) domains. It leverages infected devices as traffic relays to obscure real C2 servers, enhancing resilience against takedowns. The botnet spreads via weak Telnet/SSH credentials and known IoT vulnerabilities, with observed activity targeting internet service and gaming sectors. Researchers note shared code with other botnets, suggesting common tooling, but no specific actor has been attributed.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 3 extracted

Type Value Detail
Domain m3rnbvs5d[.]eth Details →
Domain burrberry[.]eth Details →
Domain 24carnforth2merseyside[.]sol Details →

MITRE ATT&CK TTPs 4 techniques