🟠 High | Source: The Hacker News
The Dysphoria IoT botnet has evolved its command-and-control infrastructure to use blockchain-based naming services and relay traffic through compromised devices, following a law enforcement takedown of the JackSkid botnet in March. This architectural shift makes traditional C2 disruption techniques — such as domain seizure and sinkholing — largely ineffective. The botnet poses a persistent threat to organisations with internet-exposed IoT devices, particularly those that are unpatched or using default credentials.
Security Architect’s Take: Audit your network perimeter for exposed IoT and OT devices and ensure they cannot reach arbitrary external endpoints — egress filtering and micro-segmentation are your primary controls here. Blockchain-based C2 cannot be sinkholed, so detection must rely on behavioural anomalies and DNS/network traffic analysis rather than blocklists alone.
Original advisory: Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption