Securityaffairs.Co
Dysphoria Botnet Infects 200,000 Devices Using Blockchain for C2 Operations
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Dysphoria botnet has compromised approximately 200,000 devices globally, utilizing a sophisticated command-and-control (C2) infrastructure hidden behind Ethereum and Solana blockchain domains. Originating from the jackskid and fbot malware, it targets IoT devices such as routers and cameras by exploiting weak Telnet and SSH credentials as well as known vulnerabilities like CVE-2020-8515 and CVE-2025-55182. The botnet's operators have demonstrated resilience through frequent updates and iterations, with a peak of 740,000 daily pings recorded. The malware can execute DDoS attacks with a claimed capacity of 4 Tbps, posing a significant risk for disruptions. Researchers from QiAnXin XLab and CNCERT are actively monitoring the botnet's activities and recommend device firmware updates as a preventive measure.
Key Points: • Dysphoria botnet has infected around 200,000 devices worldwide. • It uses blockchain domains to obscure its command-and-control infrastructure. • The botnet exploits weak Telnet/SSH credentials and known vulnerabilities in IoT devices.