PoC public ddos-botnet ics-ot-iot
New Dysphoria DDoS botnet spreads to 200k devices worldwide
CVE Tools coverage
A new botnet named Dysphoria has infected approximately 200,000 devices worldwide, leveraging them for DDoS attacks and traffic relays. Researchers from QiAnXin XLab found that the botnet uses blockchain-based C2 mechanisms, including Ethereum ENS and Solana SNS domains, to obscure its infrastructure. It exploits known vulnerabilities such as CVE-2025-55182 (React2Shell), CVE-2025-34152, and others in routers, cameras, and IoT devices. The botnet's operators claim a peak DDoS capacity of 4 Tbps, posing a significant threat to online services.