Skip to content

Dysphoria Botnet Infects 200,000 Devices via Blockchain-Controlled C2

In a nutshell: The rapidly growing Dysphoria botnet uses blockchain-based decentralized domains for C2 obfuscation and has already infected 200,000 devices through exploitation of known CVEs and weak credentials.

The Dysphoria botnet has infected approximately 200,000 devices worldwide and uses decentralized domain systems on Ethereum and Solana for its command and control architecture. The malware descends from older strains and is actively being further developed.

Security researchers from QiAnXin XLab have been tracking an emerging botnet family named Dysphoria since the first quarter of 2026, which has evolved from older malware strains such as jackskid and fbot. The network has already infected over 200,000 devices and undergoes continuous variant updates and technical iterations.

To obfuscate its command and control infrastructure, Dysphoria uses decentralized domain name systems: Ethereum Name Service (ENS) and Solana Name Service (SNS). The actual server addresses are hidden in forged IPv6 strings and extracted using a custom byte transformation algorithm. Infected systems send 78-byte packets as login and heartbeat signals to the command server and receive commands for DDoS attacks with configurable parameters such as duration, attack type, and target.

A variant identified in June 2026 completely dispensed with DDoS modules and instead transformed infected devices into network proxies. In this process, 155 port forwarding rules are installed on target devices via UPnP (Universal Plug and Play). Initial infection occurs through weak credentials on Telnet and SSH as well as through known vulnerabilities: CVE-2025-55182 (React2Shell), CVE-2025-34152 and CVE-2025-28137 (Totolik), CVE-2025-9528 (Linksys), as well as older flaws such as CVE-2017-17215 (Huawei) and CVE-2020-8515 (DrayTek).

Measurements from July 14 to 20, 2026 showed up to 740,000 requests daily from infected systems. The operators publicly advertise the service as a load testing tool with a claimed attack capacity of up to 4 terabits per second. To prevent infection, experts recommend timely firmware updates, changing default administrator passwords, and disabling unnecessary remote access functions on routers, cameras, and IoT devices.


Source: www.it-daily.net · Published July 30, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: