Lily
Anne

Dysphoria Botnet Turns Weak Edge Devices Into DDoS and Proxy Infrastructure

Lily Anne

Jul 30, 2026

6 min read

Dysphoria Botnet Turns Weak Edge Devices Into DDoS and Proxy Infrastructure

TL; DR

The Dysphoria DDoS botnet has compromised approximately 200,000 routers, cameras, and IoT devices worldwide by exploiting weak credentials and known vulnerabilities. Unlike traditional botnets, Dysphoria uses blockchain C2 through Ethereum ENS and Solana SNS to make its infrastructure more resilient against takedowns. A newer variant also abuses UPnP to expose internal services and turns infected devices into proxy nodes. Organizations should strengthen router security, eliminate default credentials, patch firmware promptly, restrict UPnP, and monitor network anomalies to reduce the risk of compromise.

A newly discovered DDoS botnet has silently built a network of approximately 200,000 compromised devices worldwide, highlighting how vulnerable routers, IP cameras, and IoT devices continue to fuel large-scale cyberattacks. Researchers say the Dysphoria botnet has evolved beyond traditional malware by using blockchain C2 infrastructure, making its command-and-control (C2) servers significantly harder for defenders to disrupt.

The campaign serves as another reminder that enterprise security extends well beyond laptops and smartphones. Weak router security, outdated firmware, exposed services, and default credentials can quickly turn network-edge devices into attack infrastructure.

Strengthen Endpoint Security with Hexnode UEM

How the Dysphoria DDoS botnet works

Researchers at QiAnXin XLab traced Dysphoria’s origins to the jackskid and fbot malware families. While it inherits many capabilities from its predecessors, it introduces a more resilient approach to C2 communications.

Instead of relying on conventional domains or hardcoded IP addresses, Dysphoria leverages blockchain C2 techniques through Ethereum Name Service (ENS) and Solana Name Service (SNS). These decentralized naming services resolve the infrastructure required for botnet operations.

The malware further obscures its infrastructure by hiding C2 addresses inside fabricated IPv6 strings published through blockchain naming services. After resolving the ENS or SNS record, the infected device retrieves the fake IPv6 value and applies a custom byte-transformation algorithm to extract the real C2 IP address before establishing communications with the command server. This design complicates infrastructure takedowns because defenders cannot simply seize or blacklist a traditional domain.

Once infected, devices periodically send heartbeat messages to the C2 server. The server responds with instructions that include:

  • Attack duration
  • Attack type
  • Target IP addresses
  • Configuration parameters

Earlier Dysphoria variants primarily focused on distributed denial-of-service attacks. However, researchers observed a newer June 2026 variant that shifted away from DDoS activity and instead converted infected systems into proxy nodes capable of relaying network traffic.

Why researchers are concerned

The proxy-focused variant introduces another significant capability.

Instead of merely participating in attack campaigns, compromised devices can serve as anonymous relay infrastructure for malicious operators. This makes attribution more difficult while increasing the operational value of every infected endpoint.

Researchers also found that Dysphoria abuses Universal Plug and Play (UPnP) by automatically creating up to 155 port-forwarding rules. These rules expose previously internal services directly to the internet and allow attackers to relay traffic through the compromised device, effectively turning it into a network proxy. This increases the likelihood of unauthorized access while providing threat actors with infrastructure that can conceal the true origin of malicious traffic.

This behavior expands the attack surface without requiring administrator interaction.

cybersecurity-kit
Featured Resource

Cybersecurity kit

Get essential cybersecurity resources, best practices, and strategies to strengthen enterprise security.

Download the Resource Kit

How the botnet spreads

Dysphoria relies on several well-known compromise techniques rather than a single exploit.

The malware attempts to gain access through:

  • Weak or default Telnet credentials
  • Weak SSH passwords
  • Known vulnerabilities affecting routers
  • Security flaws in IP cameras
  • Vulnerabilities in IoT devices
  • Both recent and older publicly disclosed CVEs

Many internet-connected appliances continue running outdated firmware for years, making them attractive targets for automated malware campaigns.

Organizations that overlook router security often create opportunities for attackers to compromise network-edge devices before security teams detect suspicious activity.

Why this matters for enterprises

Although routers and IoT devices may not store sensitive business data, attackers increasingly use them as operational infrastructure.

Compromised edge devices can:

  • Participate in DDoS campaigns
  • Relay malicious traffic
  • Hide attacker infrastructure
  • Expose internal services through unauthorized port forwarding
  • Create potential entry points into enterprise networks

These risks make firmware management, credential hygiene, and network visibility just as important as endpoint protection.

Organizations should regularly:

  • Eliminate default credentials
  • Enforce strong administrator passwords
  • Disable unnecessary remote management
  • Restrict UPnP where possible
  • Apply firmware updates promptly
  • Continuously monitor unusual inbound and outbound network activity

How Hexnode helps strengthen enterprise defenses

While Hexnode does not manage every category of network infrastructure or IoT hardware, it can help organizations reduce exposure across managed enterprise endpoints that interact with corporate networks.

Hexnode UEM helps organizations enforce device-compliance policies, monitor managed endpoint health, and manage operating system and application updates on supported platforms. Its Microsoft Entra Conditional Access integration can enforce access policies using compliance data from Android, iOS and macOS 11+ devices. Okta Device Trust supports access enforcement for supported macOS, Windows, iOS and Android Enterprise-enrolled devices, subject to documented prerequisites.

Hexnode XDR helps security teams identify suspicious activity across managed endpoints by correlating endpoint telemetry and behavioural signals, enriching alerts with device and policy context, mapping activity to the MITRE ATT&CK framework, supporting historical endpoint investigation, and providing response actions such as device isolation, process termination, and file quarantine. These capabilities can help security teams investigate anomalous file changes, unauthorized network beaconing, suspicious process activity and other endpoint indicators that may warrant further analysis during a suspected compromise.

FAQs

Dysphoria uses blockchain C2 infrastructure by leveraging Ethereum Name Service (ENS) and Solana Name Service (SNS) to locate its command-and-control servers. It also conceals C2 addresses inside fake IPv6 strings, making the botnet infrastructure more difficult for defenders to identify and disrupt than traditional domain-based C2 servers.

Researchers found that Dysphoria primarily targets internet-connected routers, IP cameras, and other IoT devices. It spreads by exploiting weak Telnet and SSH credentials, along with known vulnerabilities in network-edge devices running outdated firmware.

Organizations should improve router security by replacing default credentials, enforcing strong passwords, applying firmware updates promptly, disabling unnecessary remote management services, restricting UPnP where possible, and continuously monitoring for unusual inbound and outbound network activity. Managed endpoint visibility and threat detection solutions can also help identify suspicious behavior associated with botnet activity.

Conclusion

The Dysphoria DDoS botnet demonstrates how attackers continue to modernize malware while exploiting longstanding weaknesses in internet-facing devices. By combining decentralized blockchain C2 infrastructure with credential attacks, UPnP abuse, and widespread exploitation of vulnerable routers and IoT devices, the operators have created a resilient platform for both DDoS attacks and proxy operations.

Enterprises should strengthen router security, remove default credentials, maintain firmware updates, restrict unnecessary services such as UPnP, and correlate network activity with endpoint and identity telemetry. Layered visibility and proactive security controls remain essential for limiting the impact of evolving botnet campaigns.

Share

Lily Anne

Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.