Dysphoria Botnet Compromises 200,000 Devices with Blockchain-Based C2 Infrastructure
Cybersecurity researchers at QiAnXin XLab have uncovered Dysphoria, a rapidly evolving botnet that has infected approximately 200,000 devices worldwide. First detected on March 25, 2026, Dysphoria leverages compromised systems for distributed denial-of-service (DDoS) attacks and traffic relay operations, employing a sophisticated blockchain-based command-and-control (C2) mechanism to evade detection.
The botnet descends from earlier malware strains Jackskid and Fbot but introduces Ethereum ENS and Solana SNS domains to conceal C2 infrastructure. Attackers encode C2 addresses within fake IPv6 strings, decrypting them via a custom algorithm. Since its discovery, Dysphoria has undergone multiple iterations, including multi-chain support, functional separation between DDoS and proxy variants, and an updated C2 acquisition process.
In late June, XLab observed a variant that abandoned DDoS capabilities entirely, instead converting infected devices into network proxies by abusing UPnP (Universal Plug and Play) to create 155 port-forwarding rules, exposing internal services to external connections.
Dysphoria spreads by exploiting weak Telnet/SSH credentials and unpatched vulnerabilities in routers, cameras, and IoT devices. Targeted flaws include recent CVEs such as CVE-2025-55182 ("React2Shell"), CVE-2025-34152, and CVE-2025-28137 (Totolink), alongside older vulnerabilities like CVE-2017-17215 (Huawei) and CVE-2020-8515 (DrayTek).
Between July 14 and 20, XLab recorded 740,000 daily pings from infected hosts, with 239,000 connections from overseas clients and 1,800 from China. While the botnet’s operators claim a 4 Tbps DDoS capacity far below the 31.4 Tbps record set by Aisuru/Kimwolf in 2025 it remains capable of significant disruption.
The use of blockchain-based C2 resolution enhances Dysphoria’s resilience, making it harder to trace and dismantle. Despite its illicit operations, the botnet is marketed on a clearnet site as a "stress-testing" service, underscoring the blurred line between cybercrime and ostensibly legitimate tools.
TOTOLINK cybersecurity rating report: https://www.rankiteo.com/company/zioncom
"id": "ZIO1785191026",
"linkid": "zioncom",
"type": "Vulnerability",
"date": "3/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': 'Worldwide',
'type': ['Routers', 'Cameras', 'IoT devices']}],
'attack_vector': ['Exploiting weak Telnet/SSH credentials',
'Unpatched vulnerabilities in routers, cameras, and IoT '
'devices'],
'date_detected': '2026-03-25',
'description': 'Cybersecurity researchers at QiAnXin XLab have uncovered '
'*Dysphoria*, a rapidly evolving botnet that has infected '
'approximately 200,000 devices worldwide. The botnet leverages '
'compromised systems for distributed denial-of-service (DDoS) '
'attacks and traffic relay operations, employing a '
'sophisticated blockchain-based command-and-control (C2) '
'mechanism to evade detection. Dysphoria descends from earlier '
'malware strains *Jackskid* and *Fbot* but introduces Ethereum '
'ENS and Solana SNS domains to conceal C2 infrastructure. '
'Attackers encode C2 addresses within fake IPv6 strings, '
'decrypting them via a custom algorithm. The botnet has '
'undergone multiple iterations, including multi-chain support, '
'functional separation between DDoS and proxy variants, and an '
'updated C2 acquisition process. A variant observed in late '
'June abandoned DDoS capabilities entirely, converting '
'infected devices into network proxies by abusing UPnP to '
'create 155 port-forwarding rules, exposing internal services '
'to external connections.',
'impact': {'operational_impact': 'Significant disruption potential via DDoS '
'and proxy abuse',
'systems_affected': '200,000 devices (routers, cameras, IoT '
'devices)'},
'investigation_status': 'Ongoing',
'lessons_learned': 'The use of blockchain-based C2 resolution enhances botnet '
'resilience, making it harder to trace and dismantle. The '
'blurred line between cybercrime and ostensibly legitimate '
'tools (e.g., stress-testing services) complicates '
'mitigation efforts.',
'motivation': ['DDoS attacks',
'Traffic relay operations',
'Potential financial gain via stress-testing service'],
'post_incident_analysis': {'root_causes': ['Exploitation of weak credentials',
'Unpatched vulnerabilities',
'Abuse of UPnP for proxy '
'creation']},
'recommendations': ['Patch vulnerable devices',
'Strengthen Telnet/SSH credentials',
'Monitor for UPnP abuse',
'Enhance detection of blockchain-based C2 infrastructure'],
'references': [{'source': 'QiAnXin XLab'}],
'response': {'third_party_assistance': 'QiAnXin XLab'},
'title': 'Dysphoria Botnet Compromises 200,000 Devices with Blockchain-Based '
'C2 Infrastructure',
'type': 'Botnet',
'vulnerability_exploited': ['CVE-2025-55182 (React2Shell)',
'CVE-2025-34152',
'CVE-2025-28137 (Totolink)',
'CVE-2017-17215 (Huawei)',
'CVE-2020-8515 (DrayTek)']}