hacker-news · Crawled Jul 27, 2026
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
3 IoCs 1 Malware
Read original article ↗
AI Summary
The Dysphoria IoT botnet, evolving from the disrupted JackSkid infrastructure, has adopted blockchain-based command-and-control (C2) mechanisms using Ethereum Name Service (ENS) and Solana Name Service (SNS) domains. It leverages infected devices as traffic relays to obscure real C2 servers, enhancing resilience against takedowns. The botnet spreads via weak Telnet/SSH credentials and known IoT vulnerabilities, with observed activity targeting internet service and gaming sectors. Researchers note shared code with other botnets, suggesting common tooling, but no specific actor has been attributed.
AI-extracted · verify before operational use