The Dysphoria DDoS botnet has compromised around 200,000 devices worldwide, according to cybersecurity researchers tracking the fast-evolving malware family.

The botnet is used for distributed denial-of-service attacks and traffic relay operations. Its operators can either direct infected devices to flood targets with traffic or turn them into proxies that route internet connections.

Researchers first detected Dysphoria on 25 March. Since then, the malware has received several updates designed to make its infrastructure more resilient and harder to disrupt.

Blockchain domains hide command servers

Dysphoria evolved from earlier malware families known as jackskid and fbot. However, it adds a more unusual method for finding its command-and-control servers.

The malware uses Ethereum Name Service and Solana Name Service domains to obtain infrastructure details. These blockchain-based domain systems can make the botnet’s command network harder to trace and shut down.

Dysphoria also hides command server addresses inside fake IPv6 strings. The malware then recovers the real address through a custom byte-transformation process.

Once infected, devices send fixed login and heartbeat packets to the command server. The operators can then send instructions that specify the target, attack type, duration and other settings for a DDoS attack.

New variant turns infected devices into proxies

Researchers observed a newer Dysphoria variant in late June that abandoned DDoS functions altogether.

Instead, the malware focused on converting compromised devices into network proxies. It abuses Universal Plug and Play, or UPnP, to create 155 port-forwarding rules on an infected device.

Those rules can expose internal services to inbound internet connections. This gives attackers another way to route traffic through compromised devices and conceal their activity.

The separate DDoS and proxy-focused variants suggest that the operators are expanding how they can profit from the same pool of infected systems.

Weak credentials and old flaws fuel infections

The Dysphoria DDoS botnet spreads by targeting weak Telnet and SSH credentials. It also exploits known security flaws in internet-connected devices, including routers, cameras and other IoT hardware.

Researchers linked the botnet to exploitation attempts involving several newer vulnerabilities, including CVE-2025-55182, known as React2Shell, CVE-2025-34152, CVE-2025-28137 affecting Totolink devices, and CVE-2025-9528 affecting Linksys products.

Dysphoria also targets older vulnerabilities that remain unpatched on many devices. These include CVE-2017-17215 affecting Huawei equipment and CVE-2020-8515 affecting DrayTek devices.

Between 14 and 20 July, researchers recorded a peak of 740,000 daily pings from infected hosts. They also saw 239,000 connections from overseas clients and around 1,800 from China.

Based on that activity, the researchers estimate that Dysphoria currently controls about 200,000 devices.

Operators claim up to 4Tbps of DDoS capacity

The people behind Dysphoria claim their service can deliver up to 4Tbps of DDoS capacity. They promote it publicly as a stress-testing platform.

That figure is far below the 31.4Tbps record attributed to the Aisuru/Kimwolf botnet in December 2025. Even so, a 4Tbps attack could still cause serious disruption for online services and networks.

Users can reduce the risk of infection by keeping device firmware updated, changing default administrator passwords and disabling remote access when it is not needed. Stronger security settings on routers, cameras and other connected devices can also make them much harder for botnets to compromise.


0 responses to “Dysphoria DDoS Botnet Infects 200,000 Devices Worldwide”