Dysphoria is an emerging IoT botnet family active since at least the first quarter of 2026 and assessed as part of a lineage evolving from JackSkid- and fbot-related malware. It targets embedded Linux devices including routers, gateways, cameras, and similar internet-exposed appliances. Reported telemetry places its bot population at roughly 200,000 compromised devices globally, although the full scale has not been independently validated.
Dysphoria is used for distributed denial-of-service operations and for covert traffic relay through infected devices. Its architecture evolved into a hybrid model in which some compromised hosts retain DDoS functionality while others are repurposed as relay or proxy nodes that intermediate communications between bots and the real controllers. This design increases resilience and complicates takedown efforts by distancing operational command infrastructure from frontline bot communications.
A notable feature of Dysphoria is blockchain-based command-and-control discovery. The malware has used both Ethereum Name Service and Solana Name Service records to obtain infrastructure information, and it conceals controller addresses inside disguised data that is decoded locally by the malware. Later variants added custom string encryption and dynamic retrieval of relay-node lists, reflecting rapid iterative development over a short period.
Late-June variants introduced a dedicated relay/proxy build that removed DDoS modules and focused on network forwarding. This relay functionality abuses UPnP to create large numbers of port mappings on compromised gateways, exposing internal services behind NAT and allowing infected devices to function as externally reachable relay nodes. The relay component uses efficient non-blocking network I/O to shuttle traffic between inbound connections and upstream command infrastructure.
Dysphoria spreads primarily through weak Telnet and SSH credentials and through exploitation of known remote-code-execution vulnerabilities affecting IoT and edge devices. Reported exploited flaws span multiple years and vendors, indicating opportunistic targeting of poorly secured embedded Linux systems rather than a narrow victim profile.
Operational reporting indicates frequent global DDoS activity, with targeting observed across sectors such as internet services and gaming. Dysphoria has also been described as being marketed as a commercialized DDoS-for-hire service, with operators advertising multi-terabit attack capacity, though those capacity claims have not been independently confirmed. No operator attribution has been established with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
其中既包含长期被僵尸网络广泛利用的经典 IoT 漏洞(如 CVE-2017-17215、CVE-2020-8515 等),也包含近年来披露的新漏洞 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
其中既包含长期被僵尸网络广泛利用的经典 IoT 漏洞(如 CVE-2017-17215、CVE-2020-8515 等),也包含近年来披露的新漏洞 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
已监测到其利用的部分漏洞包括: CNVD-2021-79445 CVE-2013-3307 CVE-2016-20016 CVE-2017-17215 CVE-2017-5259 CVE-2025-9528 CVE-2018-14558 CVE-2020-25499 CVE-2020-8515 CVE-2025-28137 CVE-2025-34152 CVE-2025-55182 CVE-2022-35733 | 自 2026 年第一季度以来,XLAB持续追踪到一个BOT数量超过20万名为 Dysphoria 的新兴僵尸网络家族。
15 distinct techniques documented for this family, organized by ATT&CK tactic.
DDoS 样本 随后向这些分发节点发起 HTTP GET 请求: http://<node_ip>:9000/nodes?key=meowmeowmeow 。
In late June, XLab observed a variant that focused only on transforming infected devices into network proxies, and completely discarded the DDoS functionality.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IoT botnet that uses blockchain-based name services such as ENS and SNS for C2 resolution and infected-device relay nodes to obscure real controllers. It spreads via weak Telnet/SSH credentials and known IoT RCE flaws, and is described as attacking internet-service and gaming targets almost daily. A relay-only variant uses UPnP port mapping and Linux epoll to proxy traffic between outside connections and remote C2 services.
An IoT botnet that uses blockchain-based C2 resolution via Ethereum ENS and Solana SNS, conceals C2 addresses inside fake IPv6 strings, and is used for DDoS attacks and traffic relay/proxy operations. Later variants separated DDoS and relaying functionality and abused UPnP to create port forwarding rules exposing internal services.
An emerging botnet family with more than 200,000 bots, used for DDoS attacks and increasingly for covert C2 relay/proxy operations. It uses ENS/SNS blockchain domains for hidden C2 resolution, can convert infected hosts into relay nodes, supports UPnP-based port mapping, and spreads via Telnet/SSH weak credentials and exploitation of known IoT RCE vulnerabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.