Dysphoria Botnet Leverages Blockchain for Evasive C2, Compromising 200,000 Devices
A new botnet dubbed **Dysphoria** has emerged, compromising approximately 200,000 devices globally for Distributed Denial of Service (DDoS) attacks and traffic relay. Researchers at **QiAnXin XLab** have uncovered its sophisticated command-and-control (C2) mechanism, which leverages blockchain-based domain resolution for enhanced evasion and resilience.
A new and highly evasive botnet, **Dysphoria**, is actively compromising devices worldwide, with an estimated 200,000 systems now under its control. The botnet is being utilized for large-scale Distributed Denial of Service (DDoS) attacks and sophisticated traffic relay operations.

### Blockchain-Powered Evasion
According to cybersecurity researchers at **QiAnXin XLab**, **Dysphoria** represents an evolution of the 'jackskid' and 'fbot' malware families. Its key innovation lies in a covert blockchain-based command-and-control (C2) resolution mechanism.
Specifically, the botnet utilizes **Ethereum ENS** and **Solana SNS** domains to retrieve critical infrastructure information. C2 addresses are further obfuscated within fake IPv6 strings and then recovered using a custom byte-transformation algorithm, making tracing and dismantling efforts significantly more challenging.
### Rapid Evolution and Functional Separation
**XLab** first detected **Dysphoria** on March 25 and has since observed multiple iterations incorporating significant updates. These include an advanced C2 acquisition algorithm, multi-chain support, new domains, and a functional separation between its relaying and DDoS variants.
"Since the first quarter of 2026, **XLAB** has continuously tracked an emerging botnet family named **Dysphoria**, whose bot count exceeds 200,000," states **XLab's** report. "In just a few months, the family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience."
### DDoS Capabilities and Proxy Operations
Infected clients send a fixed 78-byte login and heartbeat packet to the C2, subsequently receiving DDoS attack commands. These commands dictate the duration, type, targets, and various configurable flags for the attacks.

*Source: XLAB*
By late June, **XLab** observed a variant of **Dysphoria** that exclusively focused on transforming compromised devices into network proxies, entirely discarding the DDoS functionality. This variant abuses **UPnP** (Universal Plug and Play) on infected devices to create 155 port forwarding rules, exposing internal services to inbound internet connections.
### Exploitation and Reach
The botnet propagates primarily through weak Telnet and SSH credentials, alongside known vulnerabilities in routers, cameras, and various IoT devices. Recent flaws exploited include **CVE-2025-55182** ("React2Shell"), **CVE-2025-34152**, **CVE-2025-28137** (Totolink), and **CVE-2025-9528** (Linksys). **Dysphoria** also targets older, unpatched weaknesses such as **CVE-2017-17215** (Huawei) and **CVE-2020-8515** (DrayTek).
During a monitoring period between July 14 and 20, **XLab** recorded a peak of 740,000 daily pings from infected hosts, with 239,000 connections from overseas clients and 1,800 from China. The researchers confidently estimate the current number of infected devices to be around 200,000.
Operators of **Dysphoria** claim a maximum DDoS capacity of 4 Tbps on their clearnet site, which misleadingly promotes the service as a legitimate stress-tester.
.jpg)
*Source: BleepingComputer*
While this figure is significantly lower than the 31.4 Tbps record set by the **Aisuru/Kimwolf** botnet in December 2025, a 4 Tbps capacity is still substantial enough to cause significant service disruptions.
### Protection Measures
To safeguard against botnet infections, users and IT professionals are advised to:
* Keep device firmware consistently updated.
* Change default administrator passwords immediately.
* Disable remote access features if not strictly necessary.
* Strengthen security settings on devices wherever possible.