bleeping-computer · Crawled Jul 27, 2026
New Dysphoria DDoS botnet spreads to 200k devices worldwide
2 IoCs 1 Malware 1 CVEs
Read original article ↗
AI Summary
The Dysphoria DDoS botnet has infected approximately 200,000 devices worldwide by exploiting weak credentials and known vulnerabilities in IoT devices. It evolved from 'jackskid' and 'fbot' malware, incorporating a blockchain-based command-and-control mechanism using Ethereum ENS and Solana SNS domains for resilience. The botnet conducts DDoS attacks and can transform infected devices into network proxies, leveraging UPnP to expose internal services. Its operators claim a maximum attack capacity of 4 Tbps, promoting the service on a clearnet website as a stress-testing tool.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 22 techniques
T1021.004 SSH · Lateral Movement T1059 Command and Scripting Interpreter · Execution T1071.001 Web Protocols · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1059.001 PowerShell · Execution T1070.001 Clear Windows Event Logs · Defense Evasion T1078 Valid Accounts · Defense Evasion T1098 Account Manipulation · Persistence T1110 Brute Force · Credential Access T1133 External Remote Services · Persistence T1203 Exploitation for Client Execution · Execution T1211 Exploitation for Defense Evasion · Defense Evasion T1218 System Binary Proxy Execution · Defense Evasion T1485 Data Destruction · Impact T1566 Phishing · Initial Access T1569 System Services · Execution T1570 Lateral Tool Transfer · Lateral Movement T1589 Gather Victim Identity Information · Reconnaissance T1595 Active Scanning · Reconnaissance T1599 Network Boundary Bridging · Defense Evasion T1650 Acquire Access · Resource Development