A new botnet operation leveraging decentralized naming systems to conceal its command-and-control (C2) servers has been identified by cybersecurity researchers. The network, dubbed Dysphoria, is estimated to have compromised approximately 200,000 devices worldwide.

Findings published by the independent research group QiAnXin XLab, in coordination with China's National Computer Network Emergency Response Technical Team (CNCERT), detail how Dysphoria represents an evolution of earlier malware families known as jackskid and fbot. Instead of traditional DNS entries, which are vulnerable to seizure or sinkholing, the botnet registers and resolves its C2 addresses using the Ethereum Name Service (ENS) and Solana Name Service.

This method presents significant challenges for mitigation. By resolving commands through smart contracts and public blockchain records, the operators eliminate a central point of failure. Altering or removing these domains requires control of the associated private keys, making the infrastructure highly resilient to conventional takedown strategies. Security teams relying solely on DNS or IP-based monitoring will miss this activity, as detection requires correlating on-chain data with network telemetry.

The use of blockchain-based infrastructure is not new but is becoming more systematic. Threat actors are increasingly adopting decentralized alternatives to standardize their evasion techniques and complicate defender responses. Practical countermeasures are emerging, including developing analytics to flag resolutions to known blockchain name services and building network controls to disrupt callbacks regardless of the underlying naming system.

Ultimately, the Dysphoria botnet exemplifies a broader trend where malicious actors co-opt legitimate, decentralized technologies to create more durable infrastructure. Addressing this challenge will require coordinated efforts across the cybersecurity and blockchain analytics communities to develop effective detection and response capabilities.


網絡安全研究人員識別出一種新型殭屍網絡操作,該操作利用去中心化命名系統來隱藏其命令與控制(C2)伺服器。該網絡被命名為Dysphoria,估計已在全球範圍內入侵約20萬台設備。

由獨立研究組織奇安信XLab與中國國家電腦網絡應急技術處理協調中心(CNCERT)協調發布的研究結果,詳述Dysphoria如何代表早期已知為jackskidfbot的惡意軟件家族的演進。該殭屍網絡摒棄了傳統容易被查封或陷坑的DNS記錄,轉而使用以太坊名稱服務(ENS)和Solana名稱服務來註冊和解析其C2地址。

這種方法為防禦帶來了重大挑戰。通過智能合約和公共區塊鏈記錄解析命令,操作者消除了單點故障。更改或移除這些域名需要控制相關的私鑰,使該基礎設施對常規的取締策略具有高度韌性。僅依賴DNS或基於IP監控的安全團隊將無法偵測此類活動,因為偵測需要將鏈上數據與網絡遙測數據進行關聯。

使用基於區塊鏈的基礎設施並不新見,但正變得越來越系統化。威脅行為者日益採用去中心化替代方案,以標準化其規避技術並複雜化防禦者的回應。實際的對應措施正在湧現,包括開發分析工具以標記解析到已知區塊鏈名稱服務的請求,以及建立網絡控制措施來中斷回調,無論底層命名系統為何。

總括而言,Dysphoria殭屍網絡體現了一個更廣泛的趨勢:惡意行為者濫用合法的去中心化技術,以建立更持久的基礎設施。應對此挑戰需要網絡安全與區塊鏈分析社群的協調合作,以發展有效的偵測與響應能力。

新聞來源 / Original News Source