Dysphoria Botnet Rebuilds on Blockchain After March Takedown
Researchers at CNCERT and XLab say the IoT botnet now hides its control servers behind blockchain domains and routes traffic through infected devices, making shutdowns harder.

Key points
- CNCERT and XLab are tracking an Internet-connected device botnet called Dysphoria that rebuilt itself after a March 2024 takedown of related JackSkid infrastructure.
- The operators now use blockchain-based domain names, which do not sit on the normal internet directory system and are far harder for police to seize.
- Infected devices are being used as relays, hiding the real control servers behind chains of victims.
- Researchers warn the redesign makes disruption operations significantly slower and more complicated.
A family of botnets known as Dysphoria has come back with a tougher design after police disrupted part of its network earlier this year. That is the finding from two teams tracking it: CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence unit inside Chinese security firm QiAnXin.
A botnet, for readers new to the term, is a large group of hacked devices, often home routers, cameras and set-top boxes, that criminals control remotely and rent out for attacks. Dysphoria targets Internet of Things gear, meaning the small internet-connected devices scattered through homes and offices.
The rebuild followed a law-enforcement action in March against infrastructure tied to a linked operation called JackSkid. Rather than fold, the operators changed how their network finds its bosses.
What actually changed?
The botnet swapped ordinary web addresses for blockchain-based name services, and it now bounces its traffic through the very devices it has infected. Both moves are aimed squarely at making takedowns harder.
Normal web addresses like example.com sit inside the Domain Name System, a public directory that registrars and courts can force offline. Blockchain-based names, by contrast, live inside decentralised ledgers with no central operator to serve with a warrant. Once a name is registered, there is essentially no one to call to pull it down.
The second change matters just as much. Instead of connecting infected devices straight to a command server the police could locate and seize, Dysphoria now uses compromised devices themselves as relays. Traffic from a hacked camera in one country might pass through a hacked router in another before it reaches the operator. Investigators chasing the trail hit victim after victim, not the criminal.
Why did the operators bother?
Because the March action worked, at least in part. When authorities pulled down JackSkid-related servers, the network lost reach. Rebuilding on blockchain names and victim relays is a direct response, designed so the next takedown does not land as cleanly.
As first reported by The Hacker News, the CNCERT and XLab researchers describe the new setup as materially harder to disrupt. They stop short of calling it takedown-proof. Nothing is. But the friction for investigators goes up sharply.
What it means for ordinary users
Most Dysphoria victims are not people, they are devices: routers, DVRs, IP cameras, cheap smart-home gadgets that sit online for years without updates. If yours is infected, you may never notice, beyond a slower connection or an unusually warm box.
| Item | Detail |
|---|---|
| Botnet name | Dysphoria (linked to JackSkid) |
| Tracked by | CNCERT, XLab |
| Last major disruption | March 2024 |
| New command method | Blockchain-based name services |
| New hiding technique | Infected devices used as relays |
Practical steps are unglamorous and effective. Reboot home routers and cameras occasionally, since many IoT infections do not survive a power cycle. Install firmware updates when the manufacturer offers them. Replace kit that no longer receives security patches. Change any device still running the password it came with in the box.
For businesses, the takeaway is narrower: inventory what is actually on your network. IoT gear tends to be bought by facilities teams, not IT, and it is exactly the sort of device Dysphoria feeds on.
The wider point from this episode is not new, but worth repeating. Takedowns work. They also teach the other side. Each disruption pushes serious botnet operators toward infrastructure that is harder to reach the next time round, and blockchain naming plus victim relays is where that arms race currently sits.



