New Dysphoria DDoS botnet spreads to 200k devices worldwide

Dysphoria Botnet Expands to Over 200,000 Devices Worldwide, Threatening Global Networks

A highly resilient and rapidly evolving botnet called Dysphoria has compromised over 200,000 devices worldwide, using them for distributed denial-of-service (DDoS) attacks and traffic relay operations. What’s more alarming is that this botnet leverages a covert blockchain-based command-and-control (C2) resolution mechanism to evade detection.

According to QiAnXin XLab cybersecurity researchers, Dysphoria originated from the ‘jackskid’ and ‘fbot’ malware by incorporating advanced features such as a C2 acquisition algorithm and multi-chain support. The botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while its C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm. This sophisticated approach makes it extremely challenging for security teams to track and dismantle the botnet’s infrastructure.

Since its discovery in March 2026, Dysphoria has undergone numerous updates, with researchers observing multiple iterations that added new features such as functional separation between relaying and DDoS variants. The use of blockchain in C2 operations further complicates efforts to disrupt the botnet’s activities. Infected clients send a fixed login and heartbeat packet back to the C2 server, receiving DDoS attack commands with customizable settings.

The researchers also noted that Dysphoria targets weak Telnet and SSH credentials, as well as known vulnerabilities in routers, cameras, and IoT devices. This includes recent exploits like CVE-2025-55182 (“React2Shell”), CVE-2025-34152, and CVE-2025-9528 (Linksys), among others. However, the botnet also takes advantage of older weaknesses that still persist in many devices.

In a concerning development, XLab monitored Dysphoria between July 14 and 20 and recorded a peak of 740,000 daily pings from infected hosts, with a significant number of connections coming from overseas clients. The researchers estimate the current number of infected devices to be around 200,000.

While its firepower is significantly lower than the record figure achieved by the Aisuru/Kimwolf botnet in December 2025, Dysphoria’s operators claim a maximum DDoS capacity of 4 Tbps on their clearnet site. This still poses a notable threat to global networks, particularly if not addressed promptly.

To protect against botnet infections, users should prioritize keeping their devices’ firmware up-to-date, changing default administrator passwords, disabling remote access when unnecessary, and strengthening security settings where available. It’s also essential for organizations to regularly test their systems and defenses to prevent similar incidents in the future.


Source: Bleeping Computer — 2026-07-27