Dysphoria has emerged as a fast-moving IoT botnet that has infected an estimated 200,000 devices worldwide.
The malware targets routers, cameras, gateways, and other embedded Linux systems, turning poorly protected equipment into resources for cybercriminal operations.
Its operators use a mix of Telnet and SSH password attacks alongside known software flaws to gain access.
This familiar approach is still effective because many connected devices remain exposed online, run old firmware, or use weak credentials.
Analysts at Qianxin identified the malware’s rapid evolution and its unusual use of blockchain-based domains to conceal command-and-control infrastructure.
Qianxin said in a report shared with Cyber Security News (CSN) that Dysphoria has repeatedly changed its code and network design since early 2026. The botnet is not limited to launching disruptive traffic floods.
Newer variants can convert infected machines into relay nodes, allowing operators to route traffic through compromised devices and make the real control infrastructure harder to identify or remove.
This combination of large-scale infection, adaptable code, and hidden control channels makes Dysphoria a significant concern for home users and organizations operating internet-connected equipment.
Its activity also shows why protecting connected IoT devices requires more than simply changing a device’s default password.
Dysphoria Botnet Uses Blockchain Domains
Dysphoria’s most notable feature is its use of Ethereum Name Service and Solana Name Service domains to locate its control infrastructure.
Rather than relying on one fixed server address, the malware looks up records associated with blockchain domains and obtains data that guides it toward active relay and control systems.
The technique gives operators an additional layer of resilience. Blocking a conventional domain or IP address can interrupt a botnet’s communications, but blockchain-linked records may allow attackers to update infrastructure without modifying every infected device.
This resembles other campaigns where blockchain C2 infrastructure tactics complicated efforts to track malicious servers.
Researchers observed that the bot queries ENS and SNS records, then extracts concealed network information from the returned data.
In one case, the malware uses a blockchain domain to retrieve relay-distribution nodes, which then provide the addresses used for direct command-and-control communication.
The latest samples also use modified encryption routines to hide strings and configuration data. These protections make analysis slower and help the malware avoid simple signatures, while the rotating infrastructure reduces the value of blocking individual indicators alone.
Relay Nodes Expand Threat
A separate Dysphoria variant discovered in late June removes its DDoS function and focuses entirely on creating relay proxies. It can search for network gateways that support UPnP, open ports automatically, and expose the infected system for traffic relaying.
Once active, the relay component can connect external traffic to a remote destination while using the victim device as an intermediary. The report said this creates a hybrid structure in which infected hosts support both DDoS operations and a distributed relay network.
Dysphoria spreads through weak Telnet and SSH passwords and exploits vulnerabilities affecting IoT equipment, including older flaws that remain widespread.

Similar exposure patterns were recently seen in a router loader service campaign, where attackers abused vulnerable management interfaces to deploy malicious payloads.
Monitoring between July 14 and July 20 found 4,401 confirmed active bots in China, while the peak number of overseas bots online reached 239,000.
Leaked control-panel screenshots reviewed by researchers indicated the operators maintained a botnet of roughly 200,000 devices and claimed potential DDoS capacity of up to 4 Tbps.
Device owners should change default credentials, disable Telnet and remote management where they are not essential, and apply vendor firmware updates promptly.
Organizations should also separate IoT equipment from critical systems, monitor unusual outbound connections, and review their wider IoT security management strategy to limit the impact of an infected device.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.