Summary
Key Points:
- Dysphoria, an IoT botnet, has evolved to utilize blockchain-based command-and-control (C2) and victim relays following the disruption of the JackSkid infrastructure.
- The botnet is estimated to have over 200,000 bots, with significant activity logged in China and abroad. The impact includes potential DDoS attacks targeting internet services and gaming platforms.
- Recommended actions include patching exposed IoT devices, replacing unpatchable devices, eliminating weak credentials, and disabling unnecessary remote management features.
Technical Details: Dysphoria spreads through weak Telnet and SSH credentials as well as known remote-code-execution vulnerabilities such as CVE-2025-9528. The botnet's architecture complicates takedown efforts by relying on a relay mesh of compromised devices.
MITRE ATT&CK Techniques:
- T1078 - Valid Accounts (Defense Evasion)
- T1203 - Exploit Public-Facing Application (Initial Access)
- T1204.002 - User Execution: Malicious File (Execution)
IOCs Mentioned:
- CVE-2025-9528 (Linksys E1700 command-injection flaw)
- Ethereum Name Service domains: m3rnbvs5d[.]eth, burrberry[.]eth, 24carnforth2merseyside[.]sol
Join the discussion — sign up to comment, upvote, and save articles.