New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for DDoS attacks and traffic relay operations.
Intelligence analysis by Llama

Dysphoria is a botnet that has compromised 200,000 devices worldwide, using them for DDoS attacks and traffic relay operations. It uses a covert blockchain-based command-and-control (C2) resolution mechanism, making it harder to trace and dismantle.
Imagine you have a big team of computers that can work together to make a lot of noise and make it hard for websites to work. That's basically what a botnet is. Dysphoria is a type of botnet that has taken over 200,000 computers and is using them to make a lot of noise and make it hard for websites to work. It's like a big team of computers working together to cause trouble.
Analysis
A Botnet Like No Other
Dysphoria is a botnet that has compromised 200,000 devices worldwide, using them for DDoS attacks and traffic relay operations. It uses a covert blockchain-based command-and-control (C2) resolution mechanism, making it harder to trace and dismantle. This mechanism involves using Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm.
The Rise of Dysphoria
The researchers first spotted Dysphoria on March 25 and identified multiple iterations that added meaningful updates, such as a C2 acquisition algorithm, multi-chain support, new domains, and functional separation between the relaying and DDoS variants. Since the first quarter of 2026, XLAB has continuously tracked an emerging botnet family named Dysphoria, whose bot count exceeds 200,000. In just a few months, the family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience.
The Impact of Dysphoria
The use of blockchain in C2 operations makes the overall infrastructure harder to trace and dismantle. Infected clients send a fixed 78-byte login and heartbeat packet back to the C2 and receive from the operator DDoS attack commands that include duration, type, targets, and configurable flags. DDoS attack command Source: XLAB In late June, XLab observed a variant that focused only on transforming infected devices into network proxies, and completely discarded the DDoS functionality. The malware abuses UPnP (Universal Plug and Play) on the compromised device to create 155 port forwarding rules to expose internal services to inbound internet connections. XLab's report notes that the botnet spreads through weak Telnet and SSH credentials and known vulnerabilities in routers, cameras, and various IoT devices. Among the more recent flaws exploited are CVE-2025-55182 (“ React2Shell ”), CVE-2025-34152, CVE-2025-28137 (Totolink), and CVE-2025-9528 (Linksys). However, Dysphoria also targets older weaknesses that still persist in many devices, like CVE-2017-17215 (Huawei) and CVE-2020-8515 (DrayTek).
Key points
- Dysphoria is a botnet that has compromised 200,000 devices worldwide.
- It uses a covert blockchain-based command-and-control (C2) resolution mechanism.
- The botnet spreads through weak Telnet and SSH credentials and known vulnerabilities in routers, cameras, and various IoT devices.
- Dysphoria targets older weaknesses that still persist in many devices.
If the operators of Dysphoria are caught and brought to justice, it could lead to a decrease in the number of DDoS attacks and a safer online environment. Additionally, if the vulnerabilities exploited by Dysphoria are patched, it could prevent future botnet attacks.
If the operators of Dysphoria are able to continue their activities undetected, it could lead to a significant increase in DDoS attacks and a decrease in online security. Additionally, if the vulnerabilities exploited by Dysphoria are not patched, it could allow future botnet attacks to occur.



