Dysphoria is an IoT botnet family first observed in March 2026 that targets routers, cameras, gateways, and other embedded Linux devices. It is assessed to have evolved from the jackskid and fbot malware lineages and has been associated with large-scale compromise of internet-connected devices worldwide. Its primary operational roles are distributed denial-of-service activity and traffic relay through infected hosts, including a later proxy-focused variant that repurposes compromised devices as residential or small-office relay infrastructure.
Dysphoria spreads through weak Telnet and SSH credentials and by exploiting known vulnerabilities in exposed IoT and embedded-device firmware. Reported campaigns indicate a mix of brute-force access and exploitation of remote-code-execution flaws affecting consumer and small-business networking equipment. The malware has been linked to infections of routers, surveillance cameras, repeaters, gateways, and similar embedded Linux systems.
A notable feature of Dysphoria is its resilient command-and-control design. Later variants use blockchain-based name services, including Ethereum Name Service and Solana Name Service, to obtain infrastructure information indirectly rather than relying only on static controller addresses. Researchers also reported that Dysphoria conceals controller information inside spoofed IPv6-like data and recovers the real addresses through a custom decoding routine. This architecture is intended to complicate infrastructure discovery and takedown.
Dysphoria has undergone rapid iteration since its emergence. Observed variants include DDoS-capable samples and a relay-only branch that removed attack modules and focused on covert traffic forwarding. The relay-focused variant abuses UPnP to create large numbers of port-forwarding rules on infected gateways and uses asynchronous network relaying to expose internal services and proxy operator traffic through victim devices. This increases both attacker anonymity and the operational value of each compromised host.
Telemetry and reporting associate Dysphoria with a bot population in the hundreds of thousands and near-daily malicious activity. The botnet has been marketed as a commercialized DDoS-for-hire or stress-testing service, although operator claims about maximum attack capacity have not been independently verified. No named operator has been conclusively attributed in the available reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2 CVE-2017-17215 ... Huawei HG532 ... Analysis ✓ ... RCE ✓ ... PoC ✓ ... Dysphoria botnet linked CVE-2017-17215 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
57 CVE-2020-8515 ... DrayTek Vigor2960, Vigor300B, and Vigor3900 firmware ... Analysis ✓ ... RCE ✓ ... PoC ✓ ... Dysphoria botnet linked CVE-2020-8515 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
52 CVE-2016-20016 ... MVPower TV-7104HE and TV-7108HE DVRs ... Analysis ✓ ... RCE ✓ ... PoC ✓ ... Dysphoria botnet linked CVE-2016-20016 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
71 CVE-2025-28137 ... TOTOLINK A810R firmware ... Analysis ✓ ... RCE ✓ ... PoC ✓ ... Dysphoria botnet linked CVE-2025-28137 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
67 CVE-2025-9528 ... Linksys E1700 ... Analysis ✓ ... RCE ✓ ... PoC ✓ ... Dysphoria botnet linked CVE-2025-9528 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
53 CVE-2017-5259 ... Cambium Networks cnPilot ... Analysis ✓ ... RCE ✓ ... Dysphoria botnet linked CVE-2017-5259 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
60 CVE-2020-25499 ... TOTOLINK A3002RU firmware ... Analysis ✓ ... RCE ✓ ... PoC ✓ ... Dysphoria botnet linked CVE-2020-25499 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
51 CVE-2013-3307 ... Linksys E1000, E1200, and E3200 ... Analysis ✓ ... RCE ✓ ... Dysphoria botnet linked CVE-2013-3307 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
56 CVE-2018-14558 ... Tenda AC9, AC10, and AC7 firmware ... Analysis ✓ ... RCE ✓ ... Dysphoria botnet linked CVE-2018-14558 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
64 CVE-2022-35733 ... UNIMO Technology UDR-JA1004, UDR-JA1008, and UDR-JA1016 digital video recorders ... Analysis ✓ ... RCE ✓ ... Dysphoria botnet linked CVE-2022-35733 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
39 CVE-2025-34152 ... Shenzhen Aitemi M300 Wi-Fi Repeater ... Analysis ✓ ... RCE ✓ ... PoC ✓ ... Dysphoria botnet linked CVE-2025-34152 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
7 CVE-2025-55182 ... Meta React Server Components ... Analysis ✓ ... RCE ✓ ... PoC ✓ ... Dysphoria botnet linked ... CVE-2025-55182 | In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent variants also employ modified encryption mechanisms to conceal strings and configuration data. These techniques slow down malware analysis and enable the botnet to evade basic signature-based detection mechanisms.
После блокировки прежней инфраструктуры малварь стала получать адреса управляющих серверов через Ethereum Name Service (ENS), а в начале мая разработчики оснастили ботнет поддержкой Solana Name Service (SNS).
Shadowserver said in a report that Dysphoria’s primary apparent role is DDoS activity and that it has recently added residential proxy functionality.
Shadowserver said in a report shared with Cyber Security News (CSN) that Dysphoria’s primary apparent role is DDoS activity and that it has recently added residential proxy functionality.
Кроме того, в конце июня исследователи выявили отдельную версию малвари, из которой полностью убрали все функции для проведения DDoS-атак. Вместо этого вредонос превращает зараженный девайс в сетевой прокси.
Utilisation de domaines Ethereum ENS et Solana SNS pour résoudre l’infrastructure C2
Immediately initiate an outbound connection to the actual remote c2:P (on the same port). At the underlying layer, leverage Linux's high-performance epoll-based asynchronous non-blocking I/O to bind the two connections together, implementing a bidirectional non-blocking transparent data relay.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an example of recent IoT botnet infections in broader background context.
IoT-focused botnet compromising routers, cameras, gateways, and embedded Linux devices for distributed denial-of-service attacks and residential proxy/C2 relay use.
IoT-focused botnet compromising routers, cameras, gateways, and embedded Linux devices for distributed denial-of-service attacks and residential proxy abuse.
Botnet exploiting IoT and embedded-device vulnerabilities, along with weak Telnet and SSH credentials, to enroll devices into DDoS and relay infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.