Skip to content
Data Breach

Dysphoria Botnet Infects 200,000 IoT Devices and Hides C2 Behind Blockchain Domains

Dysphoria has emerged as a fast-moving IoT botnet that has infected an estimated 200,000 devices worldwide. The malware targets routers, cameras, gateways, and other embedded Linux systems, turning poorly protected equipment into resources for cybercriminal operations. Its operators use a mix of Tel...

· Jul 28, 2026 · 5 min read · 👁 1 views
Dysphoria Botnet Infects 200,000 IoT Devices and Hides C2 Behind Blockchain Domains

Dysphoria has emerged as a fast-moving IoT botnet that has infected an estimated 200,000 devices worldwide.

The malware targets routers, cameras, gateways, and other embedded Linux systems, turning poorly protected equipment into resources for cybercriminal operations.

Its operators use a mix of Telnet and SSH password attacks alongside known software flaws to gain access.

This familiar approach is still effective because many connected devices remain exposed online, run old firmware, or use weak credentials.

Analysts at Qianxin identified the malware’s rapid evolution and its unusual use of blockchain-based domains to conceal command-and-control infrastructure.

Qianxin said in a report shared with Cyber Security News (CSN) that Dysphoria has repeatedly changed its code and network design since early 2026. The botnet is not limited to launching disruptive traffic floods.

Newer variants can convert infected machines into relay nodes, allowing operators to route traffic through compromised devices and make the real control infrastructure harder to identify or remove.

This combination of large-scale infection, adaptable code, and hidden control channels makes Dysphoria a significant concern for home users and organizations operating internet-connected equipment.

Its activity also shows why protecting connected IoT devices requires more than simply changing a device’s default password.

Dysphoria Botnet Uses Blockchain Domains

Dysphoria’s most notable feature is its use of Ethereum Name Service and Solana Name Service domains to locate its control infrastructure.

Rather than relying on one fixed server address, the malware looks up records associated with blockchain domains and obtains data that guides it toward active relay and control systems.

The technique gives operators an additional layer of resilience. Blocking a conventional domain or IP address can interrupt a botnet’s communications, but blockchain-linked records may allow attackers to update infrastructure without modifying every infected device.

This resembles other campaigns where blockchain C2 infrastructure tactics complicated efforts to track malicious servers.

Researchers observed that the bot queries ENS and SNS records, then extracts concealed network information from the returned data.

In one case, the malware uses a blockchain domain to retrieve relay-distribution nodes, which then provide the addresses used for direct command-and-control communication.

The latest samples also use modified encryption routines to hide strings and configuration data. These protections make analysis slower and help the malware avoid simple signatures, while the rotating infrastructure reduces the value of blocking individual indicators alone.

Relay Nodes Expand Threat

A separate Dysphoria variant discovered in late June removes its DDoS function and focuses entirely on creating relay proxies. It can search for network gateways that support UPnP, open ports automatically, and expose the infected system for traffic relaying.

Once active, the relay component can connect external traffic to a remote destination while using the victim device as an intermediary. The report said this creates a hybrid structure in which infected hosts support both DDoS operations and a distributed relay network.

Dysphoria spreads through weak Telnet and SSH passwords and exploits vulnerabilities affecting IoT equipment, including older flaws that remain widespread.

Commercial operation model and plans (Source - Qianxin)
Commercial operation model and plans (Source – Qianxin)

Similar exposure patterns were recently seen in a router loader service campaign, where attackers abused vulnerable management interfaces to deploy malicious payloads.

Monitoring between July 14 and July 20 found 4,401 confirmed active bots in China, while the peak number of overseas bots online reached 239,000.

Leaked control-panel screenshots reviewed by researchers indicated the operators maintained a botnet of roughly 200,000 devices and claimed potential DDoS capacity of up to 4 Tbps.

Device owners should change default credentials, disable Telnet and remote management where they are not essential, and apply vendor firmware updates promptly.

Organizations should also separate IoT equipment from critical systems, monitor unusual outbound connections, and review their wider IoT security management strategy to limit the impact of an infected device.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
IP address217.60.195.160Download/C2 server with identified FTP banner 
IP address76.164.203.171Download/C2 server with identified FTP banner 
IP address92.42.100.131Download/C2 server with identified FTP banner 
IP address78.153.155.152Download/C2 server with identified FTP banner 
Domaini.peer4you.netCritical infrastructure domain 
Domaino.peer4you.netCritical infrastructure domain 
Domainlogin.trees4sale.netRelay status reporting domain 
Domainwww.trees4sale.netCritical infrastructure domain 
Domainc2.saintpetersburgresident.ruCritical infrastructure domain 
Domainpeer.saintpetersburgresident.ruCritical infrastructure domain 
Domainkieron.androiddebugbridge.suCritical infrastructure domain 
Domaindysphoria.androiddebugbridge.suCritical infrastructure domain 
Domaintelaviv.androiddebugbridge.suCritical infrastructure domain 
Domainjerusalem.androiddebugbridge.suCritical infrastructure domain 
Domainnode.androiddebugbridge.suCritical infrastructure domain 
Domainwow.androiddebugbridge.suCritical infrastructure domain 
Blockchain domainm3rnbvs5d.ethENS domain associated with Dysphoria 
Blockchain domainburrberry.ethENS domain used for relay distribution 
Blockchain domainukranianhorseriding.ethENS domain used for network infrastructure 
Blockchain domain24carnforth2merseyside.solSNS domain used for network infrastructure 
SHA-1c1bedea261f325441fb9a75c50b11d0c8fb01ac6Partial core sample hash 
SHA-1a3b9575897c16cbf6afe3af1aa8b55171ea6edfPartial core sample hash 
SHA-198db6c78533c176f13b61405cdc3f8fad703325fPartial core sample hash 
SHA-119c1716d770ea69e8e1418d96d52222396ecb436Partial core sample hash 
SHA-1273651c02b29f1c07e3177e86c967fc45e9f30fPartial core sample hash 
SHA-10f955ff909972958098f0d4a06bcc4d6b9eea904Partial core sample hash 
SHA-14925081bdec05f64eb4f313420c82d8de957e3002Partial core sample hash 
SHA-1dcea71b9ab9de8efca301de9e2f7bf11c7132364Partial core sample hash 
SHA-1df510f6f69a5c149c216c7b3accc4f460d8cf363Partial core sample hash 
SHA-1b0782a9d6eef2ce02f734a6e5e1d8e0f9a2b65bePartial core sample hash 
SHA-1e7e1694162639ed587625432a79cfaa49f560d11Partial core sample hash 
SHA-1b7faa44ab0772047a8581bbfdd9c561e28fc66dePartial core sample hash 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you