New Dysphoria DDoS botnet spreads to 200k devices worldwide
PoC publicOur summary
A new botnet named Dysphoria has infected approximately 200,000 devices worldwide, leveraging them for DDoS attacks and traffic relays. Researchers from QiAnXin XLab found that the botnet uses blockchain-based C2 mechanisms, including Ethereum ENS and Solana SNS domains, to obscure its infrastructure. It exploits known vulnerabilities such as CVE-2025-55182 (React2Shell), CVE-2025-34152, and others in routers, cameras, and IoT devices. The botnet's operators claim a peak DDoS capacity of 4 Tbps, posing a significant threat to online services.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.