cybersecurity보안뉴스 (Boannews)· 7/29/2026, 12:59:00 AM9.0

Dysphoria Botnet Spreading Across 200,000 Devices... Urgent Need for Weak Account Settings and IoT Patching

China's National Cybersecurity Administration (CNCERT) and private security research firm XLab reported that over 200,000 IoT devices infected with the Dysphoria botnet have been identified, though verification details were not disclosed. Following the March 2025 JackSkid botnet crackdown, the Dysphoria botnet adopted blockchain-based domains and relay mechanisms to evade tracking. Attackers concealed command-and-control (C2) server locations using Ethereum Name Service (ENS) and Solana Name Service (SNS), with infected devices communicating exclusively through relays to obscure the actual C2 infrastructure. By combining RC4 encryption with UPnP port mapping and Linux epoll technology, attackers efficiently distributed a specialized relay variant. The botnet primarily spreads via weak passwords in Telnet/SSH or known IoT remote code execution (RCE) vulnerabilities like CVE-2025-9528. Researchers from Japan's National Institute of Information and Communications Technology (NICT) and international teams detected code and string sharing between Dysphoria and other botnets like Kimwolf, suggesting potential group-sharing of attack tools rather than single-organization activity. While attackers claim to offer DDoS services up to 4Tbps in the dark web, no confirmed attacks have been observed. Traditional law enforcement methods targeting central servers prove ineffective against Dysphoria's decentralized blockchain architecture. Security experts urge immediate IoT device patching, default password changes, and disabling UPnP features.

View original (보안뉴스 (Boannews)) →