Dysphoria Botnet Infects 200,000 Devices Using Blockchain for C2 Operations

Dysphoria Botnet Infects 200,000 Devices Using Blockchain for C2 Operations

First seen 28 Jul 2026, 21:24 UTC BleepingcomputerCybersecuritynewsSecurityaffairs.Coblog.xlab.qianxin.com 80% similarity 71.0

Article Content

Browse articles
ThreatCluster

The Dysphoria botnet has compromised approximately 200,000 devices globally, utilizing a sophisticated command-and-control (C2) infrastructure hidden behind Ethereum and Solana blockchain domains. Originating from the jackskid and fbot malware, it targets IoT devices such as routers and cameras by exploiting weak Telnet and SSH credentials as well as known vulnerabilities like CVE-2020-8515 and CVE-2025-55182. The botnet's operators have demonstrated resilience through frequent updates and iterations, with a peak of 740,000 daily pings recorded. The malware can execute DDoS attacks with a claimed capacity of 4 Tbps, posing a significant risk for disruptions. Researchers from QiAnXin XLab and CNCERT are actively monitoring the botnet's activities and recommend device firmware updates as a preventive measure.

Key Points: • Dysphoria botnet has infected around 200,000 devices worldwide. • It uses blockchain domains to obscure its command-and-control infrastructure. • The botnet exploits weak Telnet/SSH credentials and known vulnerabilities in IoT devices.

ThreatCluster AI How this analysis works

Timeline

2017-12-25
Public exploit for CVE-2017-17215 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2020-02-01
CVE-2020-8515 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-04-15
CVE-2025-28137 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-08-07
CVE-2025-34152 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-08-27
CVE-2025-9528 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-03
CVE-2025-55182 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-25
Dysphoria botnet first identified
QiAnXin XLab researchers detected the Dysphoria botnet, which has since evolved significantly.
Bleepingcomputer
2026-06-14
Peak activity recorded
XLab monitored 740,000 daily pings from infected hosts, indicating high botnet activity.
Bleepingcomputer
2026-07-27
Dysphoria botnet reported to have 200,000 infections
QiAnXin XLab confirms the botnet has compromised around 200,000 devices globally.
Bleepingcomputer
2026-07-28
Dysphoria botnet details disclosed
Researchers reveal the botnet's use of blockchain domains to hide C2 infrastructure.
Securityaffairs.Co

Community

Browse all →