IoT botnet Dysphoria has infected an estimated 200,000 devices worldwide and uses blockchain-based domain systems to hide its command-and-control infrastructure, according to a July 27 report by QiAnXin XLab.
XLab said the botnet emerged in late March, shortly after a multinational operation led by the United States, Canada and Germany dismantled four major IoT botnets, including JackSkid, from which Dysphoria descends.
The March operation, announced by the U.S. Justice Department, seized servers, domains and other systems used by the Aisuru, KimWolf, JackSkid and Mossad botnets. The Justice Department said those botnets had collectively infected more than 3 million devices.
XLab said Dysphoria uses Ethereum Name Service and Solana Name Service records to locate active control servers instead of traditional domain names. The researchers said that keeps infrastructure information on blockchain networks, where records cannot be removed through court orders or registrar cooperation in the same way as conventional domains.
XLab researchers said command-and-control addresses are concealed inside fake IPv6 strings and recovered through a custom byte-transformation algorithm. They said infected devices query blockchain domains to find relay-distribution nodes, which then provide addresses for direct command-and-control communication.
XLab said Dysphoria has undergone frequent code updates since it first detected the botnet on March 25. The updates added multi-chain support, new domains and a late-June variant that removed DDoS functionality and converted infected devices into network relay proxies.
The late-June variant abuses UPnP to create 155 port-forwarding rules on infected devices, XLab said. The researchers said that exposes internal services to inbound internet connections.
XLab said the botnet spreads through weak Telnet and SSH credentials and by exploiting vulnerabilities in routers, cameras and other IoT devices, including flaws dating back to 2017.
Between July 14 and 20, XLab recorded a peak of 740,000 daily pings from infected hosts, including 239,000 connections from overseas clients. The operators claim on a clearnet site marketed as a stress-testing tool that the botnet can deliver a maximum DDoS capacity of 4 Tbps.
“In just a few months, the family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience,” XLab said in its report.





