Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
FBot
Malware
FBot
Indicators of Compromise
2
Domain
ethereum[.]ens
Domain
solana[.]sns
MITRE ATT&CK TTPs
5
T1021.004
SSH
Lateral Movement
T1059
Command and Scripting Interpreter
Execution
T1071.001
Web Protocols
Command And Control
T1190
Exploit Public-Facing Application
Initial Access
T1210
Exploitation of Remote Services
Lateral Movement
Source Articles
New Dysphoria DDoS botnet spreads to 200k devices worldwide
The Dysphoria DDoS botnet has infected approximately 200,000 devices worldwide by exploiting weak credentials and known vulnerabilities in IoT devices. It evolved from 'jackskid' and 'fbot' malware, incorporating a blockchain-based command-and-control mechanism using Ethereum ENS and Solana SNS domains for resilience. The botnet conducts DDoS attacks and can transform infected devices into network proxies, leveraging UPnP to expose internal services. Its operators claim a maximum attack capacity of 4 Tbps, promoting the service on a clearnet website as a stress-testing tool.
bleeping-computer
·
19h ago