A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.
According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot' malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism.
Specifically, the botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm.
The researchers first spotted Dysphoria on March 25 and identified multiple iterations that added meaningful updates, such as a C2 acquisition algorithm, multi-chain support, new domains, and functional separation between the relaying and DDoS variants.
“Since the first quarter of 2026, XLAB has continuously tracked an emerging botnet family named Dysphoria, whose bot count exceeds 200,000,” reads XLab's report.
“In just a few months, the family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience.”
The use of blockchain in C2 operations makes the overall infrastructure harder to trace and dismantle.
Based on the researchers' analysis, infected clients send a fixed 78-byte login and heartbeat packet back to the C2 and receive from the operator DDoS attack commands that include duration, type, targets, and configurable flags.
DDoS attack command
Source: XLAB
... continue reading