Dysphoria is a botnet focused on compromising IoT and embedded Linux devices, including routers, gateways, cameras, repeaters, and similar edge infrastructure. In observed activity during 2026, it exploited multiple known vulnerabilities in such devices and also combined exploitation with weak Telnet and SSH credentials to enroll systems at scale. Compromised devices were then repurposed to provide distributed denial-of-service capacity and operational relay infrastructure. A defining characteristic of Dysphoria is its use of infected edge devices as proxy and relay nodes to obscure backend command-and-control systems and route malicious traffic through compromised infrastructure. This indicates an emphasis not only on botnet growth and DDoS capability, but also on defense evasion and post-compromise operational support. The available evidence supports characterization of Dysphoria primarily as an infrastructure-building botnet operator leveraging opportunistic exploitation and weak credential abuse against exposed embedded devices. Attribution to a specific country, sponsor, or broader named intrusion set is not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet activity exploiting known IoT and embedded-device vulnerabilities, along with weak Telnet and SSH credentials, to compromise routers, gateways, cameras, repeaters, and other embedded Linux devices for DDoS and relay infrastructure.
Repurposed compromised devices as relay infrastructure, using infected hosts to proxy traffic and hide backend command-and-control infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.