THE Dysphoria botnet has compromised over 200,000 IoT and embedded Linux devices globally, primarily targeting routers, gateways, and IP cameras. It employs weak-credential brute force and exploits known vulnerabilities to spread. The botnet's command and control (C2) mechanism utilizes blockchain to obscure its infrastructure, making it difficult to track.
XLab researchers reported that the botnet showcases a mature commercial DDoS-for-hire service with operators selling tiered plans claiming up to 4 Tbps attack capacity. Defense recommendations include changing default credentials, patching firmware, and monitoring for unusual traffic to blockchain name services.