Quick Takeaways
- Dysphoria, an IoT botnet with over 200,000 infected devices, uses blockchain-based domain names and relay networks to evade disruption and obscure command-and-control infrastructure.
- It primarily propagates via weak Telnet/SSH credentials and exploits known vulnerabilities like CVE-2025-9528 in routers and gateways.
- The botnet is capable of launching massive DDoS attacks, with potential peaks of tens of terabits per second, posing significant infrastructure threats.
Threat, Attack Techniques, and Targets
Dysphoria is a large IoT botnet that has recently changed its command and control (C2) methods. It now uses blockchain-based name services like Ethereum Name Service (ENS) and Solana Name Service (SNS). This makes it harder to disrupt the botnet. The botnet is believed to have over 200,000 infected devices, with some confirmed active devices inside China and abroad. It mainly spreads by guessing weak passwords on devices using Telnet and SSH. Dysphoria also exploits known vulnerabilities, such as CVE-2025-9528, in routers and cameras. Its targets are mainly internet service providers and gaming servers. The botnet performs distributed denial-of-service (DDoS) attacks and advertises attack strengths of up to 4 terabits per second.
Impact, Security Implications, and Remediation Guidance
Dysphoria’s new infrastructure design keeps central control hidden on blockchain and relay nodes, making it tough to disable. Its spreading methods include weak credentials and known software flaws. This botnet can cause serious disruptions to internet services and targeted networks. Organizations should patch vulnerabilities, remove devices that cannot be updated, and disable remote management features like UPnP. Default or weak passwords must be eliminated to prevent infection. If you need detailed remediation steps, consult your device vendor or cybersecurity authorities.
Stay Ahead with the Latest Tech Trends
Explore the future of technology with our detailed insights on Artificial Intelligence.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
