Researchers at XLab and CNCERT have identified that the Dysphoria IoT botnet has adopted a new tactic to evade detection and continue its operations. The botnet, which has been linked to multiple attacks on unpatched devices, has started using blockchain-based name services to facilitate communication between its infected devices and its command and control (C2) servers. This new tactic makes it harder for law enforcement to disrupt the botnet's operations.
Following the disruption of its previous infrastructure, JackSkid, the botnet has also started using infected-device relays to communicate with its C2 servers. This allows the botnet to mask its communication and make it more difficult for authorities to track its activities.
Researchers say that the botnet's new tactics make it a more resilient and adaptable threat. The use of blockchain-based name services and infected-device relays provides the botnet with a more robust defense against disruption and makes it harder for law enforcement to shut down its operations.