Securityaffairs.Co Dysphoria Botnet Infects 200,000 Devices Using Blockchain for C2 Operations
Article Content
- •Dysphoria botnet has infected around 200,000 devices worldwide.
- •It uses blockchain domains to obscure its command-and-control infrastructure.
- •The botnet exploits weak Telnet/SSH credentials and known vulnerabilities in IoT devices.
The Dysphoria botnet has compromised approximately 200,000 devices globally, utilizing a sophisticated command-and-control (C2) infrastructure hidden behind Ethereum and Solana blockchain domains. Originating from the jackskid and fbot malware, it targets IoT devices such as routers and cameras by exploiting weak Telnet and SSH credentials as well as known vulnerabilities like CVE-2020-8515 and CVE-2025-55182. The botnet's operators have demonstrated resilience through frequent updates and iterations, with a peak of 740,000 daily pings recorded. The malware can execute DDoS attacks with a claimed capacity of 4 Tbps, posing a significant risk for disruptions. Researchers from QiAnXin XLab and CNCERT are actively monitoring the botnet's activities and recommend device firmware updates as a preventive measure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Aisuru, Cncert and CVE-2017-17215 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
DDoS Attacks Intensify Despite Decrease in Frequency: Link11 Report Link11's European Cyber Report for the first half of 2026 reveals a 42% decrease in DDoS attacks on European organizations, yet the intensity of these attacks has reached unprecedented levels. The highest recorded bandwidth attack peaked at 2.3 Tbit/s, an 85% increase from the previous year. Packet rates also surged…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…