CVE Tools

New Dysphoria DDoS botnet spreads to 200k devices worldwide

BleepingComputerBy Bill Toulas

PoC public

Our summary

A new botnet named Dysphoria has infected approximately 200,000 devices worldwide, leveraging them for DDoS attacks and traffic relays. Researchers from QiAnXin XLab found that the botnet uses blockchain-based C2 mechanisms, including Ethereum ENS and Solana SNS domains, to obscure its infrastructure. It exploits known vulnerabilities such as CVE-2025-55182 (React2Shell), CVE-2025-34152, and others in routers, cameras, and IoT devices. The botnet's operators claim a peak DDoS capacity of 4 Tbps, posing a significant threat to online services.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store