Skip to content
Tech News
← Back to articles

New Dysphoria DDoS botnet spreads to 200k devices worldwide

read original more articles
Why This Matters

The Dysphoria botnet's expansion to over 200,000 devices worldwide highlights the growing sophistication of cyber threats leveraging blockchain technology for resilient command-and-control infrastructure. This development underscores the urgent need for improved cybersecurity measures for connected devices, as attackers exploit vulnerabilities to orchestrate large-scale DDoS attacks and traffic relays, posing significant risks to both industry and consumers.

Key Takeaways

A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.

According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot' malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism.

Specifically, the botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm.

The researchers first spotted Dysphoria on March 25 and identified multiple iterations that added meaningful updates, such as a C2 acquisition algorithm, multi-chain support, new domains, and functional separation between the relaying and DDoS variants.

“Since the first quarter of 2026, XLAB has continuously tracked an emerging botnet family named Dysphoria, whose bot count exceeds 200,000,” reads XLab's report.

“In just a few months, the family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience.”

The use of blockchain in C2 operations makes the overall infrastructure harder to trace and dismantle.

Based on the researchers' analysis, infected clients send a fixed 78-byte login and heartbeat packet back to the C2 and receive from the operator DDoS attack commands that include duration, type, targets, and configurable flags.

DDoS attack command

Source: XLAB

... continue reading