Cyber Security News

Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks

A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations.

Dysphoria’s evolution has been unusually aggressive, transitioning from early jackskid-derived variants to more sophisticated fbot-based implementations within weeks.

Initial samples observed in March 2026 used Ethereum Name Service (ENS) domains such as m3rnbvs5d.eth to retrieve configuration data, even embedding debug strings like “android has no compatible libc library.”

By April, newer variants replaced earlier builds and introduced distinct markers such as “hail china mainland,” signaling active development cycles and variant turnover.

A major technical leap occurred in late April when operators introduced a customized RC4-based encryption routine for string obfuscation.

This modified algorithm integrates Linear Congruential Generator (LCG) shuffling and Linear Feedback Shift Register (LFSR) operations, significantly complicating reverse engineering efforts.

The encryption redesign coincided with expanded use of ENS domains like ukranianhorseriding.eth and later burrberry.eth, alongside the adoption of Solana Name Service (SNS) domains such as 24carnforth2merseyside.sol.

These blockchain domains are used to store TXT records that dynamically deliver infrastructure data, effectively decentralizing C2 discovery.

Dysphoria’s most notable innovation lies in its covert C2 resolution mechanism. Instead of hardcoded servers, infected nodes query ENS/SNS records and extract obfuscated IP data disguised as fake IPv6 strings.

Through a custom permutation routine, the malware reconstructs valid IPv4 addresses, which are then used to contact intermediate distribution nodes.

These nodes expose endpoints such as /nodes?key=meowmeowmeow, returning active C2 relay lists. This layered approach ensures that the actual C2 servers remain hidden behind compromised devices, significantly increasing resilience against takedowns.

First observed by XLAB in Q1 2026, the botnet has already amassed more than 200,000 compromised devices, while continuously mutating its codebase and infrastructure to evade disruption.

By late June, the botnet introduced a critical architectural shift toward “relayization.” Newly identified variants removed DDoS capabilities entirely and function solely as relay/proxy nodes.

Active C2 trend (Source : XLab).

These nodes exploit UPnP to open up to 155 ports on infected routers, enabling inbound connectivity despite NAT restrictions.

Using Linux epoll-based asynchronous I/O, they establish high-efficiency bidirectional tunnels between attackers and backend infrastructure.

Dysphoria IoT Botnet

Regular heartbeat reports sent to domains such as login.trees4sale.net provide real-time status metrics including bandwidth and connection counts, effectively turning infected hosts into distributed infrastructure assets.

In parallel, Dysphoria maintains dedicated DDoS-capable payloads that utilize this relay network. Communication is structured around fixed 78-byte packets for both login and heartbeat operations.

Dysphoria botnet had 4,401 confirmed active botnets within my country, with a peak daily number of 1,801 botnets online and a peak daily C2 session count of 740,000.

Scope and Scale of Infection (Source : XLab).

This modular separation between attack execution and infrastructure support mirrors trends seen in advanced botnets and crimeware-as-a-service ecosystems.

Propagation remains heavily reliant on IoT weaknesses. Dysphoria actively exploits a mix of legacy and recent vulnerabilities, including CVE-2017-17215, CVE-2020-8515, CVE-2022-35733, and newer disclosures such as CVE-2025-9528 and CVE-2025-55182.

Telnet and SSH brute-force attacks continue to serve as the primary infection vector, ensuring broad coverage across routers, cameras, and embedded Linux systems.

Telemetry collected between July 14 and 20, 2026, indicates sustained activity, with peak daily C2 sessions reaching 740,000 and overseas botnet nodes exceeding 239,000.

DDoS Attacks (Source : XLab).

Leaked backend panels circulating on social media corroborate a stable botnet size of approximately 200,000 devices.

Operators advertise DDoS-for-hire services with claimed capacities of up to 4 Tbps, offering tiered pricing models that reflect a mature underground business operation.

Dysphoria’s global targeting spans gaming platforms, internet services, and other high-availability sectors, with near-daily attack activity observed.

Its integration of blockchain-based resolution, relay-based C2 obfuscation, and continuous variant iteration marks a notable shift in botnet design.

Complicating traditional detection and mitigation strategies while reinforcing the growing convergence between decentralized technologies and cybercrime infrastructure.

IOCs

#Hostname
1i.peer4you.net
2o.peer4you.net
3login.trees4sale.net
4www.trees4sale.net
5c2.saintpetersburgresident.ru
6peer.saintpetersburgresident.ru
7kieron.androiddebugbridge.su
8dysphoria.androiddebugbridge.su
9telaviv.androiddebugbridge.su
10jerusalem.androiddebugbridge.su
11node.androiddebugbridge.su
12wow.androiddebugbridge.su

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What Features Should AI SOC Have in 2026? A Complete Checklist Download the AI SOC Features Checklist

Mayura Kathir

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Recent Posts

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…

6 hours ago

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to…

6 hours ago

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS…

6 hours ago

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers…

7 hours ago

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also…

7 hours ago

Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code

GitLab has issued an emergency security update to address two critical vulnerabilities that could lead…

8 hours ago