The record
Written from the 3 reports below. Nothing here is unsourced.
- Dysphoria, an IoT botnet descended from the JackSkid family, has re-emerged with blockchain-based command-and-control channels and victim-operated relays after a March multinational law enforcement takedown disrupted its prior infrastructure.
- Researchers report roughly 200,000 devices have been compromised globally, primarily IoT and edge gear from vendors such as Totolink, Linksys, Huawei, and DrayTek, and are being leveraged for distributed denial-of-service attacks and traffic relay operations.
- The shift to blockchain C2 is significant because it makes takedowns harder — control traffic blends with legitimate blockchain activity and is distributed across many nodes rather than centralized servers.
- Multiple critical CVEs are cited, including pre-authentication RCE flaws in React Server Components and legacy IoT router vulnerabilities, with public proof-of-concept code circulating.
- Defenders are urged to patch or replace exposed devices, eliminate default credentials, and disable unnecessary remote management and UPnP.
- What to watch is whether Dysphoria's blockchain relay model is adopted by other botnets and whether further law enforcement actions target the new infrastructure.
What to watch next
- Monitor for blockchain-based C2 indicators in IoT telemetry.
- Patch or replace legacy IoT routers from Totolink, Linksys, Huawei, DrayTek.
- Enforce strong credentials and disable UPnP/remote management.
- Track follow-on law enforcement actions against Dysphoria infrastructure.
What changed3
Every report on this story, newest first. Times are when each outlet published.
BleepingComputer[1]
New Dysphoria DDoS botnet spreads to 200k devices worldwideThe Hacker News[2]
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid DisruptionNVD / CVE[3]
CVE-2025-55182: A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following p
Why it matters5
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- IoT device owners and operators (Totolink, Linksys, Huawei, DrayTek, generic IoT) device compromise· immediate
- Internet infrastructure and targeted services ddos disruption· immediate
- Network defenders and SOC teams detection evasion· weeks
- Organizations with unpatched IoT/edge gear patch required· days
- Blockchain and crypto infrastructure abuse for c2· longer
Coverage3
Filed from United States ×2, India ×1
Named China · United States · Germany · Canada · Japan · DrayTek · E1700 · Facebook · Huawei · Totolink · Vercel · AISURU · CNCERT · Comcast · Dysphoria · Ethereum ENS · Ethereum Name Service
- BleepingComputerNew Dysphoria DDoS botnet spreads to 200k devices worldwide[1]International· neutral

- The Hacker NewsDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption[2]English national· neutral

- NVD / CVECVE-2025-55182: A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following p[3]Wire / agency
The 3 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.