Dysphoria Botnet Employs Blockchain to Obfuscate Infrastructure
In a mere span of months, the nascent Dysphoria botnet has amassed an army of approximately 200,000 compromised devices, pioneering a sophisticated technique to obscure its command and control (C2) infrastructure behind blockchain domains. The architects of this malicious network have also ingeniously conscripted a subset of infected devices into intermediary proxy nodes, channeling communications to the actual C2 servers. This multi-tiered architectural approach exponentially complicates efforts to interdict and dismantle the botnet.
Rapid Evolution and Architectural Complexity
A comprehensive report detailing the emergence and technical architecture of Dysphoria was jointly published by China National Computer Network Emergency Response Technical Team (CNCERT/CC) and Qi-Anxin. XLAB analysts have diligently monitored the botnet’s activity since the first quarter of 2026. Over several months, the developers deployed multiple iterative upgrades to the malware, integrating novel communication protocols and strategically segregating infected devices into distinct functional roles.
The inaugural specimens of Dysphoria surfaced in late March, exhibiting code lineage tracing back to the jackskid and fbot malware families. By April, the operators had integrated a customized RC4 encryption algorithm. Subsequently, they transitioned to resolving C2 server addresses via the Ethereum Name Service (ENS) and Solana Name Service (SNS). The botnet routinely queried domains such as ukranianhorseriding.eth, burrberry.eth, and 24carnforth2merseyside.sol to establish communications.
Blockchain Evasion and Intermediary Proxy Nodes
The DNS records for these blockchain domains harbored payloads deceptively formatted as IPv6 addresses. The malware systematically extracted specific bytes from these pseudo-addresses, decrypted them, and successfully synthesized the true IPv4 address of the C2 server. Upon connection, the compromised device requested a directory of nodes functioning ostensibly as command servers. However, rigorous forensic analysis revealed that the majority of these addresses pertained to other infected devices actively operating as intermediary proxy nodes.
In late June, the operators deployed a specialized Dysphoria variant utterly devoid of offensive attack capabilities. Following initial infection, this benign-appearing program scanned the local area network for routers supporting Universal Plug and Play (UPnP) and attempted to forward 155 specific ports. Consequently, this compromised device ingested external inbound traffic and seamlessly relayed it to the authentic C2 server, effectively cloaking the ultimate destination’s IP address.
To facilitate efficient data transmission, the malware leveraged the Linux epoll mechanism, empowering the node to handle a massive volume of concurrent connections simultaneously. Furthermore, the node periodically transmitted vital telemetry back to the operators, detailing its availability status, active connection count, and available bandwidth capacity.
Propagation Mechanisms and Global Impact
Dysphoria primarily propagates by exploiting weak Telnet and Secure Shell (SSH) credentials, supplemented by exploiting publicly known vulnerabilities in Linux-based routers, IP cameras, gateways, and assorted Internet of Things (IoT) appliances. The botnet’s exploit arsenal encompasses both antiquated vulnerabilities dating back to 2013 and recently disclosed flaws from 2025. Nevertheless, brute-force credential stuffing remains its most potent and frequently utilized infection vector.
Between July 14 and July 20, 2026, analysts affirmatively identified 4,401 actively infected devices within China. Beyond its borders, the daily volume of connecting devices globally peaked at an astonishing 239,000. Intelligence gleaned from a C2 dashboard leaked across social media platforms indicates that Dysphoria’s aggregate footprint consistently hovers near the 200,000-device threshold.
The operators currently monetize access to the botnet as a premium Distributed Denial of Service (DDoS) service, audaciously claiming the capacity to launch attacks peaking at 4 Terabits per second (Tbps). Pricing tiers vary based on attack duration and required bandwidth, ranging from tens to several hundreds of dollars. Dysphoria executes attacks on a near-daily basis, indiscriminately targeting internet service providers, gaming networks, and diverse commercial organizations globally, faithfully replicating the developmental trajectory of antecedent DDoS botnet syndicates.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.