Skip to content
live markets
S&P 5007,785.76▲ 3.21%NASDAQ26,729.16▲ 2.38%DOW53,732.41▲ 2.33%GOLD4,437.30▲ 9.26%WTI82.40▲ 3.86%BRENT88.52▲ 4.47%EUR/USD1.1573▲ 1.66%USD/JPY159.31▼ 1.92%DXY99.64▼ 1.29%BTC$62,992▲ 0.20%ETH$1,881▲ 0.20%SOL$75.38▼ 0.20%TOTAL CRYPTO$2.25T▲ 0.61%
pulseofnations.
Sat, Aug 15 2026 — 13:14 UTC telegram ↗ bluesky ↗ Join the wire

Dysphoria Botnet Compromises 296K IoT Devices

A new IoT botnet named Dysphoria has infected 296,000 devices worldwide, using blockchain-based domains for command-and-control and converting victims into proxy relays.

Partner Surfshark VPN

A Special Report from Shadowserver Foundation has identified approximately 296,000 internet-connected devices compromised by the Dysphoria botnet, marking a major expansion of a fast-evolving IoT threat that combines DDoS capabilities with residential proxy operations.

The report, published August 12, classifies every listed event as critical and provides network owners with retrospective visibility into which of their devices have been hijacked. Unlike Shadowserver’s standard daily reports, this one-time dataset covers aggregated activity rather than a single 24-hour window.

From DDoS Botnet to Proxy Infrastructure

Dysphoria primarily targets internet-facing IoT systems including routers, cameras, gateways, DVRs, and other embedded Linux devices. While earlier variants focused on building a DDoS-capable botnet, newer versions have added a relay-only variant that strips out flooding functionality and instead turns compromised hosts into proxy nodes for attacker-controlled traffic.

The Shadowserver report notes that each infected endpoint can serve dual purposes: both as an attack participant and as a source of seemingly legitimate residential or small-business network traffic. This allows malicious operators to hide their origin, bypass IP-based restrictions, and relay traffic through genuine broadband connections.

Blockchain C2 Evasion

Perhaps the most distinctive feature of Dysphoria is its command-and-control architecture. The malware uses Ethereum Name Service and Solana Name Service domains to locate its control infrastructure, rather than relying on conventional IP addresses or domain names.

This blockchain-based approach complicates disruption efforts because defenders cannot rely solely on blocking a small set of conventional domains or IP addresses, forcing a fundamentally different approach to botnet takedowns.

Researchers at Chinese cybersecurity firm Qi’anxin and CNCERT have tracked Dysphoria’s evolution since early 2026, documenting repeated code changes and network redesigns. The botnet spreads through Telnet and SSH weak-password guessing as well as known remote-code-execution flaws in routers and cameras.

Dysphoria also abuses Universal Plug and Play (UPnP) to create port-forwarding rules on compromised devices, potentially mapping up to 155 ports per host. This behavior exposes internal devices or services to inbound connections and enables attackers to use infected hosts as externally reachable relays even behind network address translation.

The scale of 296,000 compromised devices represents a significant operational concern for home users and organizations operating internet-connected equipment. Administrators should ensure IoT devices use strong unique credentials, disable UPnP where not needed, apply firmware updates promptly, and monitor for unusual outbound traffic patterns.

Sources: Shadowserver Foundation Special Report; Qi’anxin XLab; Cyber Security News; CNCERT advisory

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch GeoServer Zero-Day SQL Injection Actively Exploited Read →