CVE Tools

DDoS-ботнет Dysphoria заразил более 200 000 устройств по всему миру

Хакер (xakep.ru)By Мария Нефёдова

IncidentQiAnXin XLab

Our summary

Security researchers from QiAnXin XLab and China's CNCERT have identified a new IoT botnet named Dysphoria, which has already infected over 200,000 devices globally. The malware leverages Ethereum and Solana blockchain name services to obscure its command-and-control infrastructure, making detection and takedown more difficult. Dysphoria builds on previous threats like JackSkid and fbot but adds blockchain-based DNS resolution for server addresses. It spreads through weak Telnet/SSH credentials and known remote code execution vulnerabilities such as CVE-2025-9528 (Linksys E1700), CVE-2025-28137 (Totolink), CVE-2017-17215 (Huawei), and CVE-2020-8515 (DrayTek). Researchers estimate the botnet can launch DDoS attacks up to 4 Tbps in strength.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store