Dysphoria Botnet Infects 200,000 IoT Devices, Hides C2 on Blockchain
Key Takeaways The Dysphoria botnet has compromised approximately 200,000 IoT devices globally. It targets vulnerable Linux-based IoT devices, including routers, cameras, and gateways, exploiting weak...
Key Takeaways
- The Dysphoria botnet has compromised approximately 200,000 IoT devices globally.
- It targets vulnerable Linux-based IoT devices, including routers, cameras, and gateways, exploiting weak credentials and known flaws.
- A key distinguishing feature is its use of Ethereum Name Service (ENS) and Solana Name Service (SNS) blockchain domains for command-and-control (C2) infrastructure, enhancing resilience against takedown efforts.
- Newer variants also function as relay nodes, routing traffic through compromised devices to obscure the botnet’s true C2 architecture.
- The botnet poses a significant threat due to its large scale, adaptive nature, and obfuscated C2, highlighting the critical need for robust IoT security beyond default password changes.
A sophisticated new botnet, dubbed Dysphoria, has rapidly amassed control over an estimated 200,000 Internet of Things (IoT) devices worldwide. This malware transforms inadequately secured routers, cameras, gateways, and other embedded Linux systems into components of a vast cybercriminal network. Researchers note that Dysphoria’s operators leverage a combination of brute-force attacks via Telnet and SSH, alongside exploits for known software vulnerabilities, to infiltrate target devices. This persistent, yet effective, strategy capitalizes on the widespread prevalence of exposed IoT devices that often run outdated firmware or utilize weak, easily guessed credentials.
Analysts at Qianxin have closely tracked Dysphoria’s evolution, highlighting its dynamic code changes and a novel approach to C2 infrastructure: the use of blockchain-based domains. According to Qianxin said in a report, Dysphoria has undergone continuous modifications to its codebase and network topology since early 2026. Beyond traditional distributed denial-of-service (DDoS) attacks, newer iterations of the botnet can convert compromised machines into relay nodes. This capability allows the operators to funnel malicious traffic through infected devices, thereby making the actual control infrastructure significantly more challenging to pinpoint and neutralize.
The confluence of a rapidly expanding infection base, an adaptable malware design, and obscured command channels positions Dysphoria as a serious threat. Both individual users and enterprises managing internet-connected hardware face considerable risks. The botnet’s activities underscore that effective IoT security management goes beyond simply changing default passwords.
Dysphoria Botnet Uses Blockchain Domains
Dysphoria distinguishes itself through its innovative use of Ethereum Name Service (ENS) and Solana Name Service (SNS) blockchain domains to locate its C2 infrastructure. Instead of relying on static server addresses, the malware queries records within these decentralized naming services, extracting dynamic data to guide it to active relay and control systems. This technique provides a critical layer of resilience for the botnet operators.
The adoption of blockchain domains offers significant advantages to attackers. While traditional domains or IP addresses can be blocked to disrupt a botnet’s communications, blockchain-linked records allow attackers to update their infrastructure without needing to modify every infected device. This mirrors other campaigns where blockchain C2 infrastructure tactics have complicated efforts to track malicious servers. Researchers have observed Dysphoria querying ENS and SNS records, then extracting hidden network information from the responses. For example, the malware might use a blockchain domain to fetch a list of relay distribution nodes, which then provide the precise addresses for direct C2 communications.
Further complicating analysis, recent Dysphoria samples employ modified encryption routines to obscure strings and configuration data. These protective measures hinder rapid analysis and allow the malware to evade detection by simple signature-based methods. The constantly shifting infrastructure further diminishes the effectiveness of blocking individual indicators of compromise (IoCs).
Relay Nodes Expand Threat
A distinct variant of Dysphoria, identified in late June, sheds its DDoS capabilities entirely to concentrate on establishing relay proxies. This variant actively seeks out network gateways that support Universal Plug and Play (UPnP), automatically opening ports and exposing the compromised system for traffic relay. Once activated, this relay component can forward external traffic to a remote destination, using the victim device as an intermediary. The Qianxin report indicates that this creates a hybrid operational structure where infected hosts contribute to both DDoS attacks and a distributed relay network.
Dysphoria propagates by exploiting weak Telnet and SSH credentials, along with known vulnerabilities in IoT equipment, including older flaws that remain unpatched across many devices. This pattern of exploitation mirrors recent campaigns, such as a <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/95b6a718-af0c-41b5-bde8-bae49ec8d8ea/Dysphoria-Botnet-Infects-200000-IoT-Devices-and-Hides-C2-Behind-Blockchain-Domains.pdf?AWSAccessKeyId=ASIA2F3EMEYESC2KIYRV&Signature=jKR4AOZsrbsB3IuQMXfvRDlT5EQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIEbS2a7ZMlzS6LHNJkO1aCTaRoMCdtfoBvsOhSp8Eax9AiAF7RYUas0qy%2F3CZh5nRX0%2BaAyjdddPMDbU1OjvhFVkTirzBAhgEAEaDDY5OTc1MzMwOTcwNSIMZpAPNIQ9If0aqDGxKtAEQdIVnTRWdMDhboh9JhQgGNaT7LGvg62r75J5g15Z0Tmrmu4PaypQeGLxoLMw0doWnvxefkHzFw7EB97%2B2qpIRNWMXrMivvGknWBXBsrwKppEWYXo0lcl67wk%2FBZY%2FWG05yH37OUDyTW8r8Lb%2Bdp32g1Y6OIbePNtj%2F4g4NX%2Ft%2BzmT3kZxkH8kT%2FZQedEWjP0vZV4Vdagiu2DGG3iEcRv3Uwv4QedNo4XuZnYOQ0JpjDS%2Fgv%2BELpnd%2Bu%2BBup8tG72dFJ2d1BlXi1aSeMxT8vE%2FSDxTLqOPfWzrZivmTPF5AHkBHaTGm8EPzcQ530am8Hz8z0IBHY0vEnKN4azU9sjeBbYA1itfbgyuYx127CoDS8Y3tpAmp2e2%2FbXgHSrVjN90lnFtK2grxtZ6CeRoa7On1L9ODftUkg0ZbtH1fY72mrodN%2B9cVypjJ9dQvcDUh3JbNcG40rBz0DlgiwvxUJ8WnvyI6eo9CtXXK4ZhyAkhgAzIMlbs9MQ%2BZBF%2F6nOti4EiGnR%2FzRL%2FVACI2JMmfMGb1t7Emo5Cmhbj
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.