securityaffairs.com 7/28/2026, 7:51:15 PM · external

Dysphoria botnet hides C2 on blockchain, hijacks 200k devices

Dysphoria botnet hides C2 on blockchain, hijacks 200k devices
CyberSIXT Evidence Panel

THE Dysphoria botnet has been revealed as a significant cyber threat, comprising around 200,000 infected devices globally and utilizing Ethereum and Solana blockchain domains to obscure its command infrastructure. Developed from the jackskid and fbot malware families, it has rapidly evolved with a custom RC4 encryption scheme and multi-chain blockchain C2 resolution. Its unique C2 mechanism conceals real IP addresses within fake IPv6 strings, complicating detection efforts.

Notably, a relay variant of Dysphoria allows compromised devices to function as covert relay nodes for DDoS attacks, with reported peak connections reaching 740,000. The botnet exploits weak Telnet and SSH credentials along with various vulnerabilities, threatening a wide range of industries globally.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline