Shadowserver: Dysphoria Botnet Compromises 296,000 IoT Devices for DDoS and Residential Proxy Operations

Shadowserver: Dysphoria Botnet Compromises 296,000 IoT Devices for DDoS and Residential Proxy Operations

Dysphoria Botnet Compromises Nearly 300,000 IoT Devices in Major Expansion

A recent report has uncovered a significant surge in activity from the Dysphoria botnet, which has compromised approximately 296,000 internet-connected IoT devices worldwide. The malware, known for its dual functionality, now poses a heightened threat by enabling both distributed denial-of-service (DDoS) attacks and residential proxy operations, allowing attackers to mask their origins and abuse legitimate network infrastructure.

Dysphoria primarily targets vulnerable IoT systems, including routers, cameras, gateways, DVRs, and embedded Linux devices. Early variants focused on DDoS capabilities, but newer versions have evolved to convert infected hosts into proxy relay nodes, removing DDoS functionality in some cases. This shift allows compromised devices to serve as traffic relays, enabling attackers to bypass IP-based restrictions, conduct automated abuse, or blend malicious activity with residential or small-business network traffic.

The botnet exploits weak Telnet and SSH credentials, unpatched firmware, exposed management interfaces, and unnecessary remote-access services. Notably, Dysphoria leverages Universal Plug and Play (UPnP) to create port-forwarding rules, exposing internal devices to inbound connections and enabling attackers to use infected hosts as externally reachable relays even behind network address translation (NAT).

A key concern is Dysphoria’s resilient command-and-control (C2) infrastructure, which uses Ethereum Name Service (ENS) and Solana Name Service (SNS) records to help bots locate control servers. This blockchain-based approach complicates mitigation efforts, as defenders cannot rely solely on blocking traditional domains or IP addresses.

The dataset, released as a Special Report by Shadowserver, provides retrospective visibility for affected network operators. Unlike standard daily reports, this one-time release aggregates historical data rather than a single 24-hour snapshot. While entries are timestamped August 12, 2026, defenders are advised to use the last_seen_time field to track recent activity from specific IP addresses.

The expansion of Dysphoria underscores the growing sophistication of IoT botnets, which are increasingly used for both disruptive attacks and covert proxy operations, amplifying the risks for organizations and residential networks alike.

Source: https://cyberpress.org/dysphoria-botnet-hijacks-iot/

The Shadowserver Foundation cybersecurity rating report: https://www.rankiteo.com/company/the-shadowserver-foundation

"id": "THE1786703061",
"linkid": "the-shadowserver-foundation",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of geographical region"
{'affected_entities': [{'industry': ['Consumer electronics',
                                     'Networking',
                                     'Surveillance'],
                        'location': 'Worldwide',
                        'type': 'IoT devices'}],
 'attack_vector': ['Weak Telnet/SSH credentials',
                   'Unpatched firmware',
                   'Exposed management interfaces',
                   'Unnecessary remote-access services',
                   'Universal Plug and Play (UPnP)'],
 'date_detected': '2026-08-12',
 'description': 'A recent report has uncovered a significant surge in activity '
                'from the Dysphoria botnet, which has compromised '
                'approximately 296,000 internet-connected IoT devices '
                'worldwide. The malware enables both distributed '
                'denial-of-service (DDoS) attacks and residential proxy '
                'operations, allowing attackers to mask their origins and '
                'abuse legitimate network infrastructure. The botnet targets '
                'vulnerable IoT systems, including routers, cameras, gateways, '
                'DVRs, and embedded Linux devices, and leverages weak '
                'credentials, unpatched firmware, and UPnP to create '
                "port-forwarding rules. Dysphoria's resilient "
                'command-and-control infrastructure uses Ethereum Name Service '
                '(ENS) and Solana Name Service (SNS) records, complicating '
                'mitigation efforts.',
 'impact': {'operational_impact': 'Compromised devices used for DDoS attacks '
                                  'and proxy operations',
            'systems_affected': '296,000 IoT devices'},
 'motivation': ['DDoS attacks',
                'Residential proxy operations',
                'Traffic relay for bypassing IP restrictions',
                'Automated abuse',
                'Blending malicious activity with legitimate traffic'],
 'post_incident_analysis': {'root_causes': ['Weak credentials',
                                            'Unpatched firmware',
                                            'Exposed remote-access services',
                                            'UPnP misconfigurations']},
 'references': [{'source': 'Shadowserver Special Report'}],
 'title': 'Dysphoria Botnet Compromises Nearly 300,000 IoT Devices in Major '
          'Expansion',
 'type': 'Botnet',
 'vulnerability_exploited': ['Weak credentials',
                             'Unpatched firmware',
                             'Exposed remote-access services',
                             'UPnP misconfigurations']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.