Dysphoria Botnet Uses Blockchain C2 to Resist Takedown
After a March 2026 law enforcement disruption, the Dysphoria IoT botnet rebuilt with blockchain name services and victim relays. Now at 200,000 infected devices.
The Dysphoria botnet has compromised approximately 200,000 devices worldwide, according to CNCERT and XLab, a Chinese threat-intelligence firm. The network is running DDoS attacks and traffic relay operations — the dual function being a practical architecture choice, not coincidence.
What makes Dysphoria worth tracking is how it arrived at this design. A March 2026 law enforcement operation disrupted JackSkid infrastructure — the prior botnet. What came next was a rebuild: blockchain-based name services for command-and-control, layered with infected-device relays for routing. CNCERT and XLab’s research frames the design explicitly as a response to disruption, and it’s a credible read of the engineering.
The structural logic is worth walking through. Traditional botnet C2 relies on domains, which have a known failure mode: the registrar and DNS authority can be compelled to act, and law enforcement has gotten good at this. A blockchain-based naming system removes that chokepoint — there’s no central authority to compel, no registrar to contact. Add infected-device relays to the routing layer, and you’ve also obscured the traffic path. Neither step is novel on its own; peer-to-peer botnet architectures have been around since Storm Worm in 2007. What’s shifted is the tooling. Blockchain name infrastructure is available off the shelf now. The engineering overhead to build this way has dropped.
BleepingComputer reports the 200,000 infected devices are being used as both DDoS sources and relay nodes. For organizations that operate in environments where they’re realistic DDoS targets, the relay layer is the relevant wrinkle: traffic originating from compromised residential and IoT devices doesn’t present as datacenter traffic. Volumetric mitigation tuned for the latter may have gaps.
For IoT operators, the mitigation list is familiar: update firmware where updates exist, change default credentials, segment IoT devices away from production infrastructure. The larger observation is that Dysphoria, like every large IoT botnet before it, is drawing from the same pool — millions of devices deployed, forgotten, and never updated. Law enforcement disrupts the operator. The device inventory remains.
Found this useful? Share it.


