Executive Summary
In July 2026, cybersecurity researchers identified a botnet named Dysphoria that had compromised approximately 200,000 devices globally. The botnet evolved from previous malware strains like 'jackskid' and 'fbot', incorporating a covert blockchain-based command-and-control mechanism using Ethereum ENS and Solana SNS domains. Dysphoria exploited weak Telnet and SSH credentials, as well as known vulnerabilities in routers, cameras, and IoT devices, to conduct distributed denial-of-service (DDoS) attacks and traffic relay operations. The botnet's operators claimed a maximum DDoS capacity of 4 Tbps, posing significant disruption risks.
The emergence of Dysphoria underscores the increasing sophistication of botnets leveraging blockchain technology for resilient command-and-control infrastructures. This trend highlights the urgent need for organizations to strengthen device security, regularly update firmware, and implement robust access controls to mitigate the risk of such advanced threats.
Why This Matters Now
The Dysphoria botnet's use of blockchain for command-and-control operations represents a significant evolution in cyber threats, making detection and mitigation more challenging. Organizations must proactively enhance their cybersecurity measures to defend against these advanced attack vectors.
Attack Path Analysis
The Dysphoria botnet compromised approximately 200,000 devices by exploiting weak Telnet and SSH credentials, as well as known vulnerabilities in routers and IoT devices. After initial access, the malware leveraged Universal Plug and Play (UPnP) to create port forwarding rules, exposing internal services and facilitating further exploitation. The botnet then utilized blockchain-based command-and-control (C2) mechanisms, employing Ethereum ENS and Solana SNS domains to retrieve infrastructure information, thereby establishing resilient communication channels. Infected devices were transformed into network proxies, relaying traffic and executing DDoS attacks as commanded by the operators. While specific data exfiltration activities were not reported, the botnet's ability to relay traffic suggests potential for data interception. Ultimately, the botnet's operators claimed a maximum DDoS capacity of 4 Tbps, capable of causing significant disruptions.
Kill Chain Progression
Initial Compromise
Description
The Dysphoria botnet compromised approximately 200,000 devices by exploiting weak Telnet and SSH credentials, as well as known vulnerabilities in routers and IoT devices.
Related CVEs
CVE-2025-55182
CVSS 10A pre-authentication remote code execution vulnerability in React Server Components allows unauthenticated attackers to execute arbitrary code via unsafe deserialization of HTTP request payloads.
Affected Products:
Facebook, Inc. React Server Components – 19.0.0, 19.1.0, 19.1.1, 19.2.0
Exploit Status:
exploited in the wildCVE-2025-34152
CVSS 9.8A vulnerability in Totolink routers allows remote attackers to execute arbitrary code due to improper input validation.
Affected Products:
Totolink Routers – unspecified
Exploit Status:
exploited in the wildCVE-2025-28137
CVSS 9.8A command injection vulnerability in Totolink routers allows remote attackers to execute arbitrary commands via crafted HTTP requests.
Affected Products:
Totolink Routers – unspecified
Exploit Status:
exploited in the wildCVE-2025-9528
CVSS 9.8A vulnerability in Linksys routers allows remote attackers to execute arbitrary code due to improper input validation.
Affected Products:
Linksys Routers – unspecified
Exploit Status:
exploited in the wildCVE-2017-17215
CVSS 8.8A command injection vulnerability in Huawei HG532 routers allows remote attackers to execute arbitrary commands via crafted UPnP requests.
Affected Products:
Huawei HG532 Router – unspecified
Exploit Status:
exploited in the wildCVE-2020-8515
CVSS 9.8A command injection vulnerability in DrayTek Vigor routers allows remote attackers to execute arbitrary commands via crafted HTTP requests.
Affected Products:
DrayTek Vigor Routers – unspecified
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
External Remote Services
Exploitation of Remote Services
Proxy
Network Denial of Service
Fallback Channels
Application Layer Protocol
Hardware Additions
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Dysphoria botnet's 200k compromised devices threaten network infrastructure through DDoS attacks and proxy operations, requiring enhanced egress security and zero trust segmentation.
Internet
4 Tbps DDoS capacity targets internet services and cloud infrastructure, demanding multicloud visibility, threat detection, and inline IPS protection against blockchain-based C2 operations.
Computer/Network Security
IoT device vulnerabilities exploited via weak credentials and CVEs require encrypted traffic monitoring, anomaly detection, and secure hybrid connectivity for client protection.
Consumer Electronics
Routers, cameras, and IoT devices compromised through UPnP abuse and firmware exploits necessitate kubernetes security and cloud firewall implementations for device manufacturers.
Sources
- New Dysphoria DDoS botnet spreads to 200k devices worldwidehttps://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/Verified
- CVE-2025-55182 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2025-55182Verified
- Critical Security Vulnerability in React Server Componentshttps://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-componentsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the Dysphoria botnet's ability to exploit weak credentials and vulnerabilities, thereby reducing the attacker's reach and potential impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The botnet's ability to exploit weak credentials and known vulnerabilities would likely be constrained, reducing the attacker's reach and potential impact.
Control: Zero Trust Segmentation
Mitigation: The malware's ability to expose internal services through UPnP would likely be limited, reducing the scope for further exploitation.
Control: East-West Traffic Security
Mitigation: The botnet's ability to establish resilient C2 channels would likely be constrained, limiting its capacity for lateral movement.
Control: Multicloud Visibility & Control
Mitigation: The botnet's ability to transform devices into network proxies for DDoS attacks would likely be limited, reducing the attacker's operational capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: The botnet's potential for data interception and exfiltration would likely be constrained, reducing the risk of data breaches.
The botnet's capacity to execute large-scale DDoS attacks would likely be limited, reducing the potential for significant disruptions.
Impact at a Glance
Affected Business Functions
- Network Operations
- Customer Services
- E-commerce Platforms
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of customer data and internal network configurations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict device communications and limit lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
- • Deploy Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads.
- • Utilize Multicloud Visibility & Control to monitor and manage traffic across cloud environments, identifying anomalous interactions.
- • Apply Threat Detection & Anomaly Response mechanisms to detect and respond to unusual network behaviors indicative of botnet activity.



