Cybersecurity researchers at QiAnXin XLab have discovered a botnet called Dysphoria that has infected around 200,000 devices worldwide. The malware is used for distributed denial-of-service (DDoS) attacks and network traffic relay operations.
According to the researchers, Dysphoria evolved from the jackskid and fbot malware families and comes with a blockchain-based command-and-control (C&C) feature. It uses Ethereum ENS and Solana SNS domains to locate its C&C infrastructure, with the actual server addresses hidden inside fake IPv6 strings and recovered using a custom byte-transformation algorithm.
Once a device is infected, it sends a fixed 78-byte login and heartbeat packet to the C&C server. The operator can then issue DDoS commands containing the attack type, duration, target, and additional configuration options. Researchers also identified a newer variant that removes the DDoS capability and instead turns infected devices into network proxies for traffic relay.
The malware abuses Universal Plug and Play (UPnP) to automatically create up to 155 port forwarding rules, exposing internal services to the internet and allowing remote access through the compromised device.
Dysphoria spreads through weak Telnet and SSH credentials, as well as by exploiting known vulnerabilities in routers, IP cameras, and other IoT devices. Targeted flaws include CVE-2025-55182 (React2Shell), CVE-2025-34152, CVE-2025-28137 (Totolink), and CVE-2025-9528 (Linksys). The botnet also exploits older unpatched vulnerabilities such as CVE-2017-17215 (Huawei) and CVE-2020-8515 (DrayTek).
XLab recorded a peak of 740,000 daily pings from infected devices. Researchers estimate that Dysphoria currently controls around 200,000 compromised systems worldwide. The botnet operators also advertise a claimed 4 Tbps DDoS capability on a public website, promoting the service as a legitimate stress-testing platform.