bleeping-computer · Crawled Jul 27, 2026

New Dysphoria DDoS botnet spreads to 200k devices worldwide

2 IoCs 1 Malware 1 CVEs
Read original article ↗

AI Summary

The Dysphoria DDoS botnet has infected approximately 200,000 devices worldwide by exploiting weak credentials and known vulnerabilities in IoT devices. It evolved from 'jackskid' and 'fbot' malware, incorporating a blockchain-based command-and-control mechanism using Ethereum ENS and Solana SNS domains for resilience. The botnet conducts DDoS attacks and can transform infected devices into network proxies, leveraging UPnP to expose internal services. Its operators claim a maximum attack capacity of 4 Tbps, promoting the service on a clearnet website as a stress-testing tool.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain ethereum[.]ens Details →
Domain solana[.]sns Details →

MITRE ATT&CK TTPs 22 techniques