
THE Dysphoria botnet has taken control of more than 200 000 IoT and embedded Linux devices worldwide, focusing on routers, gateways and IP cameras. It spreads by brute‑forcing weak Telnet and SSH credentials and by exploiting known vulnerabilities in the affected firmware.
The botnet’s command and control infrastructure relies on Ethereum and Solana blockchain domains to hide the true addresses of its servers. Researchers observed a custom RC4 encryption scheme protecting communications and a technique that masks real IP addresses inside fabricated IPv6 strings.
A relay version of Dysphoria lets compromised devices act as covert nodes for distributed denial‑of‑service attacks, with peak concurrent connections observed at around 740 000. The operators advertise a commercial DDoS‑for‑hire service offering tiered plans that claim up to four terabits per second of attack bandwidth.
XLab first detected the activity on 28 July 2026 and continued to see activity through 4 August 2026. The malware family appears to have evolved from the jackskid and fbot strains, though no specific threat actor group has been publicly attributed.
Administrators should replace default usernames and passwords on all Internet‑facing devices and apply the latest firmware patches from vendors. Monitoring network traffic for unusual queries to blockchain name services and blocking outbound connections to known Ethereum or Solana resolver endpoints can help uncover hidden C2 channels. Disabling unnecessary Telnet and SSH services, or restricting them to trusted management networks, reduces the attack surface.
Maintaining an up‑to‑date inventory of IoT assets and segmenting them from critical systems limits lateral movement if a device is compromised. Regularly reviewing logs for spikes in outbound traffic to blockchain‑related domains provides an early warning of possible botnet activity.