The Dysphoria botnet has compromised about 296,000 internet-connected devices, largely routers, cameras, gateways, and other embedded Linux or IoT systems, and is being used to launch distributed denial-of-service (DDoS) attacks while also relaying attacker traffic through infected hosts. Reporting citing Shadowserver says the botnet has expanded beyond disruption to include residential proxy functionality, allowing malicious traffic and command-and-control relay activity to appear as if it originates from ordinary home or small-business internet connections.
The exposed population reflects devices that are already compromised, rather than victims of a single confirmed exploit chain, and prior reporting linked Dysphoria infections to Telnet and SSH password attacks alongside exploitation of known vulnerabilities. Defenders are being urged to investigate exposed management services, update firmware, replace weak or reused credentials, disable unnecessary remote administration, segment IoT devices from critical networks, and retire unsupported hardware that can no longer be secured.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Shadowserver reported that Dysphoria has recently added residential proxy functionality, allowing operators to relay their own traffic through infected devices. This makes malicious traffic appear to come from ordinary residential or small-business internet connections, increasing attacker anonymity and complicating mitigation.
According to Shadowserver, Dysphoria's primary apparent role is distributed denial-of-service activity, with infected devices able to contribute coordinated attack traffic. The references describe this as a key use of the botnet's compromised IoT footprint.
Shadowserver reported a critical special dataset covering roughly 296,000 compromised devices tied to the Dysphoria botnet, primarily routers, cameras, gateways, and embedded Linux or IoT equipment. The dataset focuses on devices already observed as compromised rather than attributing all infections to a single exploit or malware file.
The references state that a previously reported Dysphoria IoT infection campaign used password attacks against Telnet and SSH alongside known vulnerabilities to compromise devices. No explicit date is provided for that earlier campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.