Dysphoria Botnet Infects 200,000 Devices Using Blockchain DNS and IoT Exploits
A newly identified DDoS botnet called Dysphoria compromised approximately 200,000 Linux-based IoT devices globally, with daily infections peaking at 239,000 between July 14 and 20, 2026. The malware spreads by exploiting weak Telnet and SSH credentials alongside multiple known remote code execution vulnerabilities targeting routers, gateways, and cameras. Dysphoria uses blockchain-based name resolution systems — Ethereum Name Service and Solana Name Service — to retrieve multi-stage command-and-control server addresses, making infrastructure takedowns harder. Infected devices are repurposed either as DDoS bots or as relay nodes that open up to 155 forwarded ports via UPnP, effectively masking the real C2 server behind victim devices. Operators reportedly advertised up to 4 Tbps of attack capacity, and defenders are advised to disable Telnet, apply patches, block port 9000 traffic, and disable UPnP to mitigate exposure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in