Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GhostNet: Chinese Cyber Espionage Network Linked to PLA Attacks
July 28, 2026
Tengu Mirai Botnet Reboots IoT Devices, Resists Termination Attempts
July 28, 2026
Critical LegacyHive Exploits Bypass Windows Security, Even With July 2026 Patches
July 28, 2026
Home/CyberSecurity News/Dysphoria Botnet Infects 200,000 IoT Devices, Hides C2 on Blockchain
CyberSecurity News

Dysphoria Botnet Infects 200,000 IoT Devices, Hides C2 on Blockchain

Key Takeaways The Dysphoria botnet has compromised approximately 200,000 IoT devices globally. It targets vulnerable Linux-based IoT devices, including routers, cameras, and gateways, exploiting weak...

Sarah simpson
Sarah simpson
July 28, 2026 3 Min Read
4 0

Key Takeaways

  • The Dysphoria botnet has compromised approximately 200,000 IoT devices globally.
  • It targets vulnerable Linux-based IoT devices, including routers, cameras, and gateways, exploiting weak credentials and known flaws.
  • A key distinguishing feature is its use of Ethereum Name Service (ENS) and Solana Name Service (SNS) blockchain domains for command-and-control (C2) infrastructure, enhancing resilience against takedown efforts.
  • Newer variants also function as relay nodes, routing traffic through compromised devices to obscure the botnet’s true C2 architecture.
  • The botnet poses a significant threat due to its large scale, adaptive nature, and obfuscated C2, highlighting the critical need for robust IoT security beyond default password changes.

A sophisticated new botnet, dubbed Dysphoria, has rapidly amassed control over an estimated 200,000 Internet of Things (IoT) devices worldwide. This malware transforms inadequately secured routers, cameras, gateways, and other embedded Linux systems into components of a vast cybercriminal network. Researchers note that Dysphoria’s operators leverage a combination of brute-force attacks via Telnet and SSH, alongside exploits for known software vulnerabilities, to infiltrate target devices. This persistent, yet effective, strategy capitalizes on the widespread prevalence of exposed IoT devices that often run outdated firmware or utilize weak, easily guessed credentials.

Table Of Content

  • Key Takeaways
  • Dysphoria Botnet Uses Blockchain Domains
  • Relay Nodes Expand Threat

Analysts at Qianxin have closely tracked Dysphoria’s evolution, highlighting its dynamic code changes and a novel approach to C2 infrastructure: the use of blockchain-based domains. According to Qianxin said in a report, Dysphoria has undergone continuous modifications to its codebase and network topology since early 2026. Beyond traditional distributed denial-of-service (DDoS) attacks, newer iterations of the botnet can convert compromised machines into relay nodes. This capability allows the operators to funnel malicious traffic through infected devices, thereby making the actual control infrastructure significantly more challenging to pinpoint and neutralize.

The confluence of a rapidly expanding infection base, an adaptable malware design, and obscured command channels positions Dysphoria as a serious threat. Both individual users and enterprises managing internet-connected hardware face considerable risks. The botnet’s activities underscore that effective IoT security management goes beyond simply changing default passwords.

Dysphoria Botnet Uses Blockchain Domains

Dysphoria distinguishes itself through its innovative use of Ethereum Name Service (ENS) and Solana Name Service (SNS) blockchain domains to locate its C2 infrastructure. Instead of relying on static server addresses, the malware queries records within these decentralized naming services, extracting dynamic data to guide it to active relay and control systems. This technique provides a critical layer of resilience for the botnet operators.

The adoption of blockchain domains offers significant advantages to attackers. While traditional domains or IP addresses can be blocked to disrupt a botnet’s communications, blockchain-linked records allow attackers to update their infrastructure without needing to modify every infected device. This mirrors other campaigns where blockchain C2 infrastructure tactics have complicated efforts to track malicious servers. Researchers have observed Dysphoria querying ENS and SNS records, then extracting hidden network information from the responses. For example, the malware might use a blockchain domain to fetch a list of relay distribution nodes, which then provide the precise addresses for direct C2 communications.

Further complicating analysis, recent Dysphoria samples employ modified encryption routines to obscure strings and configuration data. These protective measures hinder rapid analysis and allow the malware to evade detection by simple signature-based methods. The constantly shifting infrastructure further diminishes the effectiveness of blocking individual indicators of compromise (IoCs).

Relay Nodes Expand Threat

A distinct variant of Dysphoria, identified in late June, sheds its DDoS capabilities entirely to concentrate on establishing relay proxies. This variant actively seeks out network gateways that support Universal Plug and Play (UPnP), automatically opening ports and exposing the compromised system for traffic relay. Once activated, this relay component can forward external traffic to a remote destination, using the victim device as an intermediary. The Qianxin report indicates that this creates a hybrid operational structure where infected hosts contribute to both DDoS attacks and a distributed relay network.

Dysphoria propagates by exploiting weak Telnet and SSH credentials, along with known vulnerabilities in IoT equipment, including older flaws that remain unpatched across many devices. This pattern of exploitation mirrors recent campaigns, such as a <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/95b6a718-af0c-41b5-bde8-bae49ec8d8ea/Dysphoria-Botnet-Infects-200000-IoT-Devices-and-Hides-C2-Behind-Blockchain-Domains.pdf?AWSAccessKeyId=ASIA2F3EMEYESC2KIYRV&Signature=jKR4AOZsrbsB3IuQMXfvRDlT5EQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIEbS2a7ZMlzS6LHNJkO1aCTaRoMCdtfoBvsOhSp8Eax9AiAF7RYUas0qy%2F3CZh5nRX0%2BaAyjdddPMDbU1OjvhFVkTirzBAhgEAEaDDY5OTc1MzMwOTcwNSIMZpAPNIQ9If0aqDGxKtAEQdIVnTRWdMDhboh9JhQgGNaT7LGvg62r75J5g15Z0Tmrmu4PaypQeGLxoLMw0doWnvxefkHzFw7EB97%2B2qpIRNWMXrMivvGknWBXBsrwKppEWYXo0lcl67wk%2FBZY%2FWG05yH37OUDyTW8r8Lb%2Bdp32g1Y6OIbePNtj%2F4g4NX%2Ft%2BzmT3kZxkH8kT%2FZQedEWjP0vZV4Vdagiu2DGG3iEcRv3Uwv4QedNo4XuZnYOQ0JpjDS%2Fgv%2BELpnd%2Bu%2BBup8tG72dFJ2d1BlXi1aSeMxT8vE%2FSDxTLqOPfWzrZivmTPF5AHkBHaTGm8EPzcQ530am8Hz8z0IBHY0vEnKN4azU9sjeBbYA1itfbgyuYx127CoDS8Y3tpAmp2e2%2FbXgHSrVjN90lnFtK2grxtZ6CeRoa7On1L9ODftUkg0ZbtH1fY72mrodN%2B9cVypjJ9dQvcDUh3JbNcG40rBz0DlgiwvxUJ8WnvyI6eo9CtXXK4ZhyAkhgAzIMlbs9MQ%2BZBF%2F6nOti4EiGnR%2FzRL%2FVACI2JMmfMGb1t7Emo5Cmhbj

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Scammers Impersonate ShinyHunters, Blackmail Breach Victims with Fake Webcam Videos

Next Post

Critical Arista VeloCloud Orchestrator Zero-Day Actively Exploited

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Dysphoria Botnet Infects 200,000 IoT Devices, Hides C2 on Blockchain
July 28, 2026
Scammers Impersonate ShinyHunters, Blackmail Breach Victims with Fake Webcam Videos
July 28, 2026
Critical Progress LoadMaster Flaws Let Attackers Execute Commands, Gain Root Access
July 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us