Search...

Large-scale activity of “Dysphoria” botnet targeting IoT devices detected

Large-scale activity of “Dysphoria” botnet targeting IoT devices detected

A new IoT botnet known as “Dysphoria” has reportedly infected approximately 200,000 devices worldwide. The rapidly spreading malware primarily targets routers, surveillance cameras, network gateways and other embedded systems running Linux-based operating systems. Compromised devices are used to conduct distributed denial-of-service (DDoS) attacks and covertly relay network traffic.

The “Dysphoria” botnet gains initial access to devices by conducting password attacks against Telnet and SSH services and exploiting known vulnerabilities in IoT firmware. The use of default or weak credentials, failure to apply firmware updates and exposure of remote management services significantly increase the likelihood of infection. Since early 2026, the botnet has reportedly undergone multiple changes to its code and network architecture, acquiring new operational capabilities.

One of the malware’s key technical features is its use of Ethereum Name Service (ENS) and Solana Name Service (SNS) blockchain domains to conceal its command-and-control (C2) infrastructure. Instead of connecting directly to a fixed server address, “Dysphoria” queries records associated with blockchain domains and retrieves concealed network information from them. The obtained information directs the malware to intermediary traffic-relay nodes and active C2 servers.

The use of blockchain-based domains complicates the identification and disruption of the botnet’s infrastructure. If a conventional domain or IP address is blocked, the operators can update the relevant blockchain records and redirect infected devices to alternative infrastructure. This eliminates the need to update the malware separately on each compromised device. Recent variants also employ modified encryption mechanisms to conceal strings and configuration data. These techniques slow down malware analysis and enable the botnet to evade basic signature-based detection mechanisms.

A separate “Dysphoria” variant identified in late June was found to have abandoned its DDoS functionality and shifted its focus entirely to establishing an intermediary proxy network. The variant identifies network gateways that support the Universal Plug and Play (UPnP) protocol, automatically opens ports and makes infected systems accessible for external traffic relaying. As a result, the operators can route internet traffic through compromised devices to remote systems, thereby concealing its true source and the underlying C2 infrastructure.

The principal infrastructure indicators identified in connection with the botnet include the IP addresses 217.60.195.160, 76.164.203.171, 92.42.100.131 and 78.153.155.152, as well as the domains i.peer4you.net, o.peer4you.net, www.trees4sale.net and dysphoria.androiddebugbridge.su. In addition, the blockchain domains m3rnbvs5d.eth, burrberry.eth, ukranianhorseriding.eth and 24carnforth2merseyside.sol have been identified as components of the botnet’s network and relay infrastructure.

© 2011-2026 All rights reserved