IoT Botnet Dysphoria Exploits Unpatched Devices to Spread

Researchers at XLab and CNCERT have discovered that the Dysphria IoT botnet has started using blockchain-based name services and infected-device relays to further its operations after a disruption to its previous infrastructure, JackSkid.

Researchers at XLab and CNCERT have identified that the Dysphoria IoT botnet has adopted a new tactic to evade detection and continue its operations. The botnet, which has been linked to multiple attacks on unpatched devices, has started using blockchain-based name services to facilitate communication between its infected devices and its command and control (C2) servers. This new tactic makes it harder for law enforcement to disrupt the botnet's operations.

Following the disruption of its previous infrastructure, JackSkid, the botnet has also started using infected-device relays to communicate with its C2 servers. This allows the botnet to mask its communication and make it more difficult for authorities to track its activities.

Researchers say that the botnet's new tactics make it a more resilient and adaptable threat. The use of blockchain-based name services and infected-device relays provides the botnet with a more robust defense against disruption and makes it harder for law enforcement to shut down its operations.

Source: The Hacker News