logo

New Dysphoria DDoS botnet spreads to 200k devices worldwide

ID: 290aea88-1db4-5d8c-b357-5c13952568e8

STIX ID: report--290aea88-1db4-5d8c-b357-5c13952568e8

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Bill Toulas

...
...

QiAnXin XLab researchers describe Dysphoria, a rapidly evolving global botnet (~200,000 infected IoT and router devices) that uses Ethereum ENS and Solana SNS domains to hide command-and-control data and encodes C2 addresses inside fake IPv6 strings recovered via a custom algorithm; variants provide DDoS capabilities (operators claim up to 4 Tbps) and, in later iterations, proxy/port-forwarding functionality via abused UPnP. The bot spreads via weak Telnet/SSH credentials and exploits multiple known CVEs (including several 2025 flaws and older vulnerabilities like CVE-2017-17215 and CVE-2020-8515), with XLab observing heavy telemetry and frequent technical updates; recommended mitigations include patching firmware, changing default credentials, and disabling unnecessary remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.