Ethical Hacking News
The Dysphoria botnet has been making waves in the cybersecurity community with its use of blockchain domains to hide its command infrastructure. This malicious entity consists of approximately 200,000 devices worldwide that have been compromised, using Ethereum and Solana blockchain domains to conceal its command servers. The attackers behind this botnet have added custom encryption schemes and introduced covert relay nodes, making it a sophisticated cyber threat that is difficult to track down.
The Dysphoria botnet consists of approximately 200,000 compromised devices worldwide.The attackers use Ethereum and Solana blockchain domains to hide their command infrastructure.The botnet has evolved from the jackskid and fbot malware families and rapidly iterated since its discovery in March 2026.The botnet uses a heavily modified RC4 algorithm with custom encryption schemes and hidden relay nodes.The attackers claim to have 4 Tbps of DDoS capacity on their public promotion site, selling attack packages ranging from tens to hundreds of dollars.The Dysphoria botnet targets industries globally, covering multiple sectors including internet services and gaming.
The world of cyber threats is ever-evolving, and one recent development that stands out is the emergence of the Dysphoria botnet. This malicious entity has been making waves in the cybersecurity community, with researchers uncovering its existence and capabilities.
According to a report by QiAnXin XLab, jointly with China's CNCERT, the Dysphoria botnet consists of approximately 200,000 devices worldwide that have been compromised. The attackers behind this botnet have been utilizing Ethereum and Solana blockchain domains to hide their command infrastructure. This is a clever move, as it makes it difficult for security researchers to track down the source of the attacks.
The Dysphoria botnet has evolved from the jackskid and fbot malware families and has been rapidly iterating since its discovery in March 2026. In just four months, the attackers have added a custom RC4 encryption scheme, multi-chain blockchain C2 resolution, and even introduced a separate variant that converts infected devices into covert relay nodes.
The most interesting aspect of this botnet is its use of blockchain domains to conceal its command infrastructure. The attackers query ENS domains like burrberry.eth and ukranianhorseriding.eth, as well as the Solana domain 24carnforth2merseyside.sol. These domains contain fake IPv6 strings that hide the real IP addresses. When a device infected by the malware sends data to its command server, it uses a custom byte-transformation function to recover the real IP address.
The encryption scheme used in this botnet is heavily modified RC4 algorithm. The attackers have added two extra phases: a linear congruential generator that shuffles the S-box five times after initialization, and a linear feedback shift register that steps during keystream generation, XORing the output with additional rotations and bit shifts before the final byte is applied.
Another notable feature of this botnet is its ability to turn infected devices into hidden relay nodes. Once an attacker gains access, it broadcasts a UPnP discovery request across the local network, finds the gateway router, and maps 155 port forwarding rules. This allows the attackers to initiate outbound connections to the actual remote device on the same port.
The Dysphoria botnet has been using weak Telnet and SSH credentials and a range of known vulnerabilities in routers, cameras, and IoT devices to spread its malware. The attackers claim to have 4 Tbps of DDoS capacity on their public promotion site, selling attack packages ranging from tens to hundreds of dollars depending on duration and bandwidth.
The report highlights that the Dysphoria botnet's targets are located globally, covering multiple industries including internet services and gaming. The victims are characterized by their wide distribution and broad industry coverage. Continuous monitoring shows that its attack activity occurs almost daily, maintaining a high level of activity overall.
In conclusion, the Dysphoria botnet is a sophisticated cyber threat that leverages blockchain domains to evade detection. Its use of custom encryption schemes, hidden relay nodes, and DDoS attacks make it a formidable opponent for cybersecurity researchers and organizations alike.
Related Information:
https://www.ethicalhackingnews.com/articles/Dysphoria-Botnet-A-Sophisticated-Cyber-Threat-Leveraging-Blockchain-Domains-for-Evasion-ehn.shtml
https://securityaffairs.com/196182/malware/dysphoria-botnet-uses-blockchain-domains-to-hide-c2-infrastructure.html
https://cybersecuritynews.com/dysphoria-botnet-infects-iot-devices/
Published: Tue Jul 28 15:12:47 2026 by llama3.2 3B Q4_K_M