Executive Summary
In July 2026, cybersecurity researchers identified a new IoT botnet named Dysphoria, which has infected approximately 200,000 devices globally. Following the March 2026 law enforcement takedown of the JackSkid botnet, Dysphoria emerged with enhanced resilience by integrating blockchain-based command-and-control (C2) mechanisms and utilizing infected devices as relays to obscure its infrastructure. This evolution complicates traditional disruption methods and poses significant challenges to cybersecurity defenses.
The adoption of blockchain name services for C2 resolution and the use of victim devices as relays represent a concerning trend in botnet development. These tactics not only enhance the botnet's resilience against takedown efforts but also indicate a shift towards more sophisticated and decentralized control structures in cyber threats.
Why This Matters Now
The emergence of Dysphoria underscores the increasing sophistication of IoT botnets, highlighting the urgent need for enhanced security measures to protect vulnerable devices and prevent large-scale DDoS attacks.
Attack Path Analysis
The Dysphoria IoT botnet exploited weak credentials and known vulnerabilities to compromise devices, escalated privileges to maintain control, moved laterally to infect additional devices, established resilient command and control using blockchain-based name services, exfiltrated data through infected-device relays, and impacted networks by launching DDoS attacks.
Kill Chain Progression
Initial Compromise
Description
Dysphoria exploited weak Telnet and SSH credentials, along with known IoT vulnerabilities, to gain initial access to devices.
Related CVEs
CVE-2025-55182
CVSS 10A command injection vulnerability in certain IoT devices allows remote attackers to execute arbitrary commands.
Affected Products:
VendorName ProductName – VersionRange
Exploit Status:
exploited in the wildCVE-2025-34152
CVSS 9.4An authentication bypass vulnerability in specific IoT devices permits unauthorized access to device functions.
Affected Products:
VendorName ProductName – VersionRange
Exploit Status:
exploited in the wildCVE-2025-28137
CVSS 9.8A buffer overflow vulnerability in certain IoT devices allows remote attackers to cause a denial of service or execute arbitrary code.
Affected Products:
VendorName ProductName – VersionRange
Exploit Status:
exploited in the wildCVE-2025-9528
CVSS 7.2A remote code execution vulnerability in specific IoT devices allows attackers to execute arbitrary code without authentication.
Affected Products:
VendorName ProductName – VersionRange
Exploit Status:
exploited in the wildCVE-2017-17215
CVSS 8.8A command injection vulnerability in Huawei HG532 routers allows remote attackers to execute arbitrary commands.
Affected Products:
Huawei HG532 – All versions
Exploit Status:
exploited in the wildCVE-2020-8515
CVSS 9.8A command injection vulnerability in DrayTek Vigor routers allows remote attackers to execute arbitrary commands.
Affected Products:
DrayTek Vigor – All versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Compromise Infrastructure: Botnet
Application Layer Protocol: Web Protocols
Dynamic Resolution: Domain Generation Algorithms
Proxy: External Proxy
Network Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Network Segmentation
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical infrastructure IoT devices vulnerable to Dysphoria botnet's blockchain C2, requiring enhanced east-west traffic security and zero trust segmentation for operational technology protection.
Telecommunications
Network infrastructure IoT components exposed to botnet lateral movement and command control, necessitating multicloud visibility and egress security policy enforcement across hybrid connectivity.
Manufacturing
Industrial IoT and automation systems at risk from encrypted botnet traffic, demanding threat detection capabilities and secure hybrid connectivity between operational technology environments.
Health Care / Life Sciences
Medical IoT devices vulnerable to blockchain-based botnet infiltration, requiring HIPAA-compliant encrypted traffic monitoring and anomaly detection for patient data protection compliance.
Sources
- Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruptionhttps://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.htmlVerified
- New Dysphoria DDoS botnet spreads to 200k devices worldwidehttps://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/Verified
- Dysphoria Botnet: ENS/SNS C2 και Relay/proxy Victim Nodes | SecNewshttps://www.secnews.gr/724116/dysphoria-botnet-ens-sns-victim-relays/Verified
- IoT Botnet - Check Point Softwarehttps://www.checkpoint.com/cyber-hub/network-security/what-is-iot/iot-botnet/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the Dysphoria IoT botnet incident as it would likely limit the botnet's ability to move laterally, escalate privileges, and exfiltrate data, thereby reducing the overall impact and blast radius of the attack.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The botnet's ability to exploit weak credentials and known vulnerabilities to gain initial access to devices would likely be constrained.
Control: Zero Trust Segmentation
Mitigation: The botnet's ability to escalate privileges to maintain control over compromised devices would likely be constrained.
Control: East-West Traffic Security
Mitigation: The botnet's ability to move laterally by scanning for and infecting additional vulnerable IoT devices within the network would likely be constrained.
Control: Multicloud Visibility & Control
Mitigation: The botnet's ability to establish resilient command and control using blockchain-based name services would likely be constrained.
Control: Egress Security & Policy Enforcement
Mitigation: The botnet's ability to exfiltrate data through infected-device relays, obfuscating the origin of the traffic, would likely be constrained.
The botnet's ability to launch DDoS attacks using compromised devices, causing service disruptions, would likely be constrained.
Impact at a Glance
Affected Business Functions
- Network Operations
- Customer Services
- Data Management
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of customer data and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement strong, unique credentials and disable default accounts on all IoT devices.
- • Regularly update and patch IoT devices to address known vulnerabilities.
- • Deploy network segmentation to limit lateral movement of potential threats.
- • Utilize egress security controls to monitor and restrict outbound traffic from IoT devices.
- • Establish comprehensive threat detection mechanisms to identify and respond to anomalous activities promptly.



