The Dysphoria DDoS botnet has compromised approximately 200,000 routers, cameras, and IoT devices worldwide by exploiting weak credentials and known vulnerabilities. Unlike traditional botnets, Dysphoria uses blockchain C2 through Ethereum ENS and Solana SNS to make its infrastructure more resilient against takedowns. A newer variant also abuses UPnP to expose internal services and turns infected devices into proxy nodes. Organizations should strengthen router security, eliminate default credentials, patch firmware promptly, restrict UPnP, and monitor network anomalies to reduce the risk of compromise.
A newly discovered DDoS botnet has silently built a network of approximately 200,000 compromised devices worldwide, highlighting how vulnerable routers, IP cameras, and IoT devices continue to fuel large-scale cyberattacks. Researchers say the Dysphoria botnet has evolved beyond traditional malware by using blockchain C2 infrastructure, making its command-and-control (C2) servers significantly harder for defenders to disrupt.
The campaign serves as another reminder that enterprise security extends well beyond laptops and smartphones. Weak router security, outdated firmware, exposed services, and default credentials can quickly turn network-edge devices into attack infrastructure.
Researchers at QiAnXin XLab traced Dysphoria’s origins to the jackskid and fbot malware families. While it inherits many capabilities from its predecessors, it introduces a more resilient approach to C2 communications.
Instead of relying on conventional domains or hardcoded IP addresses, Dysphoria leverages blockchain C2 techniques through Ethereum Name Service (ENS) and Solana Name Service (SNS). These decentralized naming services resolve the infrastructure required for botnet operations.
The malware further obscures its infrastructure by hiding C2 addresses inside fabricated IPv6 strings published through blockchain naming services. After resolving the ENS or SNS record, the infected device retrieves the fake IPv6 value and applies a custom byte-transformation algorithm to extract the real C2 IP address before establishing communications with the command server. This design complicates infrastructure takedowns because defenders cannot simply seize or blacklist a traditional domain.
Once infected, devices periodically send heartbeat messages to the C2 server. The server responds with instructions that include:
Attack duration
Attack type
Target IP addresses
Configuration parameters
Earlier Dysphoria variants primarily focused on distributed denial-of-service attacks. However, researchers observed a newer June 2026 variant that shifted away from DDoS activity and instead converted infected systems into proxy nodes capable of relaying network traffic.
Why researchers are concerned
The proxy-focused variant introduces another significant capability.
Instead of merely participating in attack campaigns, compromised devices can serve as anonymous relay infrastructure for malicious operators. This makes attribution more difficult while increasing the operational value of every infected endpoint.
Researchers also found that Dysphoria abuses Universal Plug and Play (UPnP) by automatically creating up to 155 port-forwarding rules. These rules expose previously internal services directly to the internet and allow attackers to relay traffic through the compromised device, effectively turning it into a network proxy. This increases the likelihood of unauthorized access while providing threat actors with infrastructure that can conceal the true origin of malicious traffic.
This behavior expands the attack surface without requiring administrator interaction.
Featured Resource
Cybersecurity kit
Get essential cybersecurity resources, best practices, and strategies to strengthen enterprise security.
Dysphoria relies on several well-known compromise techniques rather than a single exploit.
The malware attempts to gain access through:
Weak or default Telnet credentials
Weak SSH passwords
Known vulnerabilities affecting routers
Security flaws in IP cameras
Vulnerabilities in IoT devices
Both recent and older publicly disclosed CVEs
Many internet-connected appliances continue running outdated firmware for years, making them attractive targets for automated malware campaigns.
Organizations that overlook router security often create opportunities for attackers to compromise network-edge devices before security teams detect suspicious activity.
Why this matters for enterprises
Although routers and IoT devices may not store sensitive business data, attackers increasingly use them as operational infrastructure.
Compromised edge devices can:
Participate in DDoS campaigns
Relay malicious traffic
Hide attacker infrastructure
Expose internal services through unauthorized port forwarding
Create potential entry points into enterprise networks
These risks make firmware management, credential hygiene, and network visibility just as important as endpoint protection.
Organizations should regularly:
Eliminate default credentials
Enforce strong administrator passwords
Disable unnecessary remote management
Restrict UPnP where possible
Apply firmware updates promptly
Continuously monitor unusual inbound and outbound network activity
How Hexnode helps strengthen enterprise defenses
While Hexnode does not manage every category of network infrastructure or IoT hardware, it can help organizations reduce exposure across managed enterprise endpoints that interact with corporate networks.
Hexnode UEM helps organizations enforce device-compliance policies, monitor managed endpoint health, and manage operating system and application updates on supported platforms. Its Microsoft Entra Conditional Access integration can enforce access policies using compliance data from Android, iOS and macOS 11+ devices. Okta Device Trust supports access enforcement for supported macOS, Windows, iOS and Android Enterprise-enrolled devices, subject to documented prerequisites.
Hexnode XDR helps security teams identify suspicious activity across managed endpoints by correlating endpoint telemetry and behavioural signals, enriching alerts with device and policy context, mapping activity to the MITRE ATT&CK framework, supporting historical endpoint investigation, and providing response actions such as device isolation, process termination, and file quarantine. These capabilities can help security teams investigate anomalous file changes, unauthorized network beaconing, suspicious process activity and other endpoint indicators that may warrant further analysis during a suspected compromise.
FAQs
What makes the Dysphoria DDoS botnet different from traditional botnets?
Dysphoria uses blockchain C2 infrastructure by leveraging Ethereum Name Service (ENS) and Solana Name Service (SNS) to locate its command-and-control servers. It also conceals C2 addresses inside fake IPv6 strings, making the botnet infrastructure more difficult for defenders to identify and disrupt than traditional domain-based C2 servers.
Which devices does the Dysphoria botnet target?
Researchers found that Dysphoria primarily targets internet-connected routers, IP cameras, and other IoT devices. It spreads by exploiting weak Telnet and SSH credentials, along with known vulnerabilities in network-edge devices running outdated firmware.
How can organizations reduce the risk of Dysphoria infections?
Organizations should improve router security by replacing default credentials, enforcing strong passwords, applying firmware updates promptly, disabling unnecessary remote management services, restricting UPnP where possible, and continuously monitoring for unusual inbound and outbound network activity. Managed endpoint visibility and threat detection solutions can also help identify suspicious behavior associated with botnet activity.
Conclusion
The Dysphoria DDoS botnet demonstrates how attackers continue to modernize malware while exploiting longstanding weaknesses in internet-facing devices. By combining decentralized blockchain C2 infrastructure with credential attacks, UPnP abuse, and widespread exploitation of vulnerable routers and IoT devices, the operators have created a resilient platform for both DDoS attacks and proxy operations.
Enterprises should strengthen router security, remove default credentials, maintain firmware updates, restrict unnecessary services such as UPnP, and correlate network activity with endpoint and identity telemetry. Layered visibility and proactive security controls remain essential for limiting the impact of evolving botnet campaigns.
Secure Internet-Facing Devices
Harden edge devices, enforce security policies, and detect botnet activity with Hexnode UEM and XDR.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.