"Since the first quarter of 2026, XLAB has continuously tracked an emerging botnet family named Dysphoria, whose bot count exceeds 200,000," QiAnXin XLab researchers report — a concise summary of a fast-evolving threat that combines old infection techniques with a modern, covert command channel.
Blockchain-based C2: Ethereum ENS and Solana SNS conceal infrastructure
Dysphoria departs from many IoT botnets by resolving command-and-control (C2) infrastructure through blockchain naming systems. According to QiAnXin XLab, the malware uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, and it conceals C2 addresses inside fake IPv6 strings that are recovered via a custom byte‑transformation algorithm. That covert resolution mechanism, the researchers say, makes the overall infrastructure harder to trace and dismantle.
Roots and rapid evolution: from jackskid and fbot to multi‑variant family
XLab traced Dysphoria’s lineage to earlier malware families, noting it "evolved from the ‘jackskid’ and ‘fbot' malware" and was first observed on March 25. In a span of months the family accumulated multiple iterations: the additions include a C2 acquisition algorithm, multi‑chain support, new domains, and a clear functional split between relaying and DDoS variants. "In just a few months, the family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience," the report states.
Propagation vectors and the CVEs being exploited
The botnet spreads through weak Telnet and SSH credentials and by exploiting known vulnerabilities in routers, cameras, and other IoT devices. XLab lists recent flaws the malware targets by identifier: CVE-2025-55182 ("React2Shell"), CVE-2025-34152, CVE-2025-28137 (Totolink), and CVE-2025-9528 (Linksys). Dysphoria also leverages older, still‑widespread vulnerabilities such as CVE-2017-17215 (Huawei) and CVE-2020-8515 (DrayTek).
DDoS capacity, proxy pivot, and the mechanics of control
Operators behind Dysphoria use infected devices for both distributed denial-of-service attacks and traffic relaying. XLab’s analysis shows infected clients send a fixed 78‑byte login and heartbeat packet back to the C2 and receive commands that specify DDoS duration, type, targets, and configurable flags. The botnet’s operators advertise a maximum DDoS capacity of 4 Tbps on a clearnet site that markets the service as a legitimate stress‑tester — a level XLab notes is enough to cause notable disruptions, even if it is lower than the 31.4 Tbps record noted for another botnet in December 2025.
In late June, researchers observed a variant that abandoned DDoS functionality entirely and focused on converting compromised devices into network proxies. That version abuses UPnP on infected devices to create 155 port‑forwarding rules, exposing internal services to inbound internet connections and turning otherwise dormant devices into relay points.
Telemetry and scale: what XLab observed July 14–20
XLab monitored Dysphoria from July 14 through July 20 and recorded a peak of 740,000 daily pings from infected hosts. During that window they counted 239,000 connections from overseas clients and 1,800 from China. From these measurements the researchers estimate the botnet’s infected device population at roughly 200,000 devices worldwide.
What this means for technologists, enterprises, and end users
- Technologists and security teams: expect resilient C2 channels that use public blockchains and obfuscated IPv6 strings; detection will need to account for non‑traditional resolution methods and the fixed 78‑byte heartbeat observed by XLab.
- Enterprises and procurement leaders: vendor devices remain a primary vector. The report underscores the need for timely firmware updates and configuration controls on routers, cameras, and other IoT equipment.
- End users and operators of small networks: the researchers reiterate basic but effective mitigations — keep device firmware up to date, change default administrator passwords, disable remote access if not necessary, and strengthen available security settings.
Dysphoria’s combination of old exploiting techniques and modern obfuscation — telnet/SSH abuse and well‑known CVE exploitation paired with ENS/SNS‑based C2 resolution and fake IPv6 encoding — presents a familiar but harder‑to‑dislodge adversary. The botnet’s operator claim of a 4 Tbps capacity, its measured hundreds of thousands of active pings, and the late‑June pivot to proxying all point to an adaptable toolset that will demand defenders pay attention to naming systems on public blockchains and to the oft‑neglected security posture of everyday internet‑connected devices.




