The Dysphoria botnet has compromised roughly 200,000 devices globally, using them for massive DDoS attacks and traffic relay. Its covert blockchain‑based command‑and‑control system makes detection and takedown increasingly difficult.
Key Takeaways
- Dysphoria has infected over 200,000 devices worldwide.
- It leverages Ethereum ENS and Solana SNS domains for hidden C2 communication.
- The botnet claims a peak DDoS capacity of up to 4 Tbps.
Technical Overview
Researchers at QiAnXin XLab report that Dysphoria evolved from the “jackskid” and “fbot” malware families by adding a covert blockchain‑based command‑and‑control (C2) resolution layer. The botnet queries Ethereum ENS and Solana SNS domains for infrastructure data, while C2 addresses are embedded in fake IPv6 strings and recovered via a custom byte‑transformation algorithm.
Historical Background
The first sighting on March 25 revealed a rapidly iterating family. Since early 2026, XLab has tracked multiple variants that introduced multi‑chain support, new domains, and a functional split between proxy‑only and DDoS‑capable versions. Frequent updates demonstrate a resilience that outpaces many legacy botnets.
Comparison Table
| Feature | Dysphoria | Aisuru/Kimwolf |
|---|---|---|
| Infected Devices | ≈200,000 | ≈500,000 |
| Maximum DDoS Capacity | 4 Tbps | 31.4 Tbps |
| Blockchain‑Based C2 | Yes | No |
Why This Matters
BozokMedia analysis shows that the integration of blockchain domains for C2 communication raises the bar for attribution, making traditional takedown strategies less effective and exposing a new frontier in cyber‑weaponry.
"Blockchain‑enabled C2 makes botnets far more resilient and harder to dismantle," says cybersecurity analyst Dr. Maya Patel.
Mitigation Recommendations
Keep device firmware up‑to‑date, replace default administrator passwords, disable remote access unless required, and harden all available security settings. Regularly audit IoT devices for open Telnet/SSH ports and known CVEs.
Frequently Asked Questions
Q1: Can home IoT devices be compromised?
A: Yes—any device with weak credentials or outdated firmware is a potential entry point.
Q2: Is the claimed 4 Tbps capacity realistic?
A: While lower than the record 31.4 Tbps seen from Aisuru/Kimwolf, 4 Tbps is still sufficient to cause major service disruptions.