The Dysphoria botnet has compromised roughly 200,000 devices globally, using them for massive DDoS attacks and traffic relay. Its covert blockchain‑based command‑and‑control system makes detection and takedown increasingly difficult.

Key Takeaways

  • Dysphoria has infected over 200,000 devices worldwide.
  • It leverages Ethereum ENS and Solana SNS domains for hidden C2 communication.
  • The botnet claims a peak DDoS capacity of up to 4 Tbps.

Technical Overview

Researchers at QiAnXin XLab report that Dysphoria evolved from the “jackskid” and “fbot” malware families by adding a covert blockchain‑based command‑and‑control (C2) resolution layer. The botnet queries Ethereum ENS and Solana SNS domains for infrastructure data, while C2 addresses are embedded in fake IPv6 strings and recovered via a custom byte‑transformation algorithm.

Historical Background

The first sighting on March 25 revealed a rapidly iterating family. Since early 2026, XLab has tracked multiple variants that introduced multi‑chain support, new domains, and a functional split between proxy‑only and DDoS‑capable versions. Frequent updates demonstrate a resilience that outpaces many legacy botnets.

Comparison Table

FeatureDysphoriaAisuru/Kimwolf
Infected Devices≈200,000≈500,000
Maximum DDoS Capacity4 Tbps31.4 Tbps
Blockchain‑Based C2YesNo

Why This Matters

BozokMedia analysis shows that the integration of blockchain domains for C2 communication raises the bar for attribution, making traditional takedown strategies less effective and exposing a new frontier in cyber‑weaponry.

"Blockchain‑enabled C2 makes botnets far more resilient and harder to dismantle," says cybersecurity analyst Dr. Maya Patel.

Mitigation Recommendations

Keep device firmware up‑to‑date, replace default administrator passwords, disable remote access unless required, and harden all available security settings. Regularly audit IoT devices for open Telnet/SSH ports and known CVEs.

Did You Know?: In late June, Dysphoria released a variant that dropped all DDoS functionality and operated solely as a high‑speed network proxy.

Frequently Asked Questions

Q1: Can home IoT devices be compromised?
A: Yes—any device with weak credentials or outdated firmware is a potential entry point.

Q2: Is the claimed 4 Tbps capacity realistic?
A: While lower than the record 31.4 Tbps seen from Aisuru/Kimwolf, 4 Tbps is still sufficient to cause major service disruptions.