A Devastating DDoS Botnet Has Emerged, Threatening Global Stability
A massive and highly resilient distributed denial of service (DDoS) botnet has been spreading rapidly across the globe, compromising over 200,000 devices in its wake. Dubbed Dysphoria, this botnet is using a novel combination of blockchain-based command-and-control (C2) resolution mechanisms and sophisticated networking techniques to evade detection and wreak havoc on online infrastructure.
Researchers at QiAnXin XLab have been tracking Dysphoria since March 25, when the botnet first emerged. Since then, it has undergone numerous iterations, with each update adding significant new features and capabilities. The botnet’s operators claim a maximum DDoS capacity of 4 Tbps, although this is significantly lower than the record figure set by the Aisuru/Kimwolf botnet in December last year.
Dysphoria’s infrastructure is particularly noteworthy for its use of blockchain-based C2 resolution mechanisms, which make it far more difficult to track and dismantle. The botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm.
The botnet spreads through weak Telnet and SSH credentials as well as known vulnerabilities in routers, cameras, and other IoT devices. Researchers have identified several specific flaws that have been exploited by Dysphoria, including CVE-2025-55182 (“React2Shell”) and CVE-2020-8515 (DrayTek). The botnet also targets older weaknesses that still persist in many devices.
XLab monitored the botnet between July 14 and 20 and recorded a peak of 740,000 daily pings from infected hosts, 239,000 connections from overseas clients, and 1,800 from China. While these numbers may seem staggering, they are likely only a small fraction of the total number of devices compromised by Dysphoria.
So what does this mean for individuals and organizations? For starters, it’s essential to keep your devices’ firmware up to date, change default administrator passwords, disable remote access if not necessary, and strengthen security settings where available. While these measures may not be foolproof, they can significantly reduce the risk of infection.
Moreover, Dysphoria serves as a stark reminder of the importance of proactive cybersecurity measures. As researchers at QiAnXin XLab have noted, “The family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience.” It’s clear that botnets like Dysphoria will continue to evolve and adapt, making it essential for security teams to stay ahead of the curve.
As we face this new threat, it’s more crucial than ever to prioritize robust cybersecurity practices. By doing so, we can mitigate the impact of attacks like Dysphoria and prevent disruptions to critical online infrastructure.
Source: Bleeping Computer — 2026-07-27