Researchers reported that the Dysphoria IoT botnet, a lineage linked to JackSkid, changed its command-and-control design after a March law-enforcement disruption targeting JackSkid infrastructure. According to CNCERT and XLab, the operators replaced more traditional C2 dependencies with Ethereum Name Service (ENS) and Solana Name Service (SNS) records, allowing infected devices to resolve controller information through blockchain-based naming systems and making infrastructure takedowns more difficult.
XLab said Dysphoria evolved rapidly from late March through June, adding ENS resolution, SNS resolution, a relay-only variant, and UPnP port mapping to help compromised devices traverse NAT environments. The botnet is reported to spread primarily through weak Telnet and SSH credentials, along with some known IoT remote-code-execution flaws, and it also uses infected devices as relay nodes to obscure backend controllers; however, the reported bot counts and attack scale have not been independently verified, and no operator or victim organizations were publicly identified.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Researchers said Dysphoria incorporated UPnP-based port mapping to traverse NAT devices. This capability was part of the botnet's post-disruption evolution described as occurring from late March through June.
XLab's analysis described a relay-only Dysphoria variant that uses compromised infected devices as relay nodes for command-and-control. The design was intended to further complicate takedown efforts by obscuring core infrastructure.
Researchers reported that Dysphoria shifted to blockchain-based name services for command-and-control, specifically using Ethereum Name Service and Solana Name Service records. This marked a technical evolution in the botnet's infrastructure after the disruption.
XLab said Dysphoria underwent rapid development from late March through June after the March 19 disruption. The changes included work on new command-and-control mechanisms intended to make takedowns harder.
BleepingComputer reported that QiAnXin XLab estimated Dysphoria had spread to roughly 200,000 devices globally and was being used for DDoS attacks and proxy/traffic relay operations. The report also said researchers observed heavy botnet activity in mid-July and that operators advertised up to 4 Tbps of DDoS capacity.
XLab published an analysis on July 25 describing Dysphoria's rapid development and its use of blockchain naming services, relay nodes, and NAT traversal techniques. The report linked these changes to the aftermath of the March 19 disruption.
The XLab report says CNCERT and QiAnXin had been tracking the Dysphoria botnet since Q1 2026. This establishes the earliest explicit observation window for the emerging botnet family before the March disruption and later architectural changes.
Monitoring for July 14–20, 2026 found 4,401 active bots in mainland China, a peak of 239,000 overseas bots online daily, and near-daily global DDoS activity affecting sectors including internet services and gaming. This provided a specific operational snapshot of Dysphoria's scale and active use beyond the previously reported general bot population estimate.
The new reference says a newer relay variant of Dysphoria was discovered on 2026-06-25. This version removes DDoS modules and uses UPnP plus Linux epoll-based transparent forwarding to expose infected devices as relay infrastructure.
According to the reporting, a law-enforcement disruption targeting JackSkid occurred on March 19. This disruption prompted subsequent changes in the related Dysphoria botnet's command-and-control architecture.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
blog.xlab.qianxin.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceblog.xlab.qianxin.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.