CVE Tools
Back to feed
Incident QiAnXin XLab ddos-botnet ics-ot-iot

DDoS-ботнет Dysphoria заразил более 200 000 устройств по всему миру

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Security researchers from QiAnXin XLab and China's CNCERT have identified a new IoT botnet named Dysphoria, which has already infected over 200,000 devices globally. The malware leverages Ethereum and Solana blockchain name services to obscure its command-and-control infrastructure, making detection and takedown more difficult. Dysphoria builds on previous threats like JackSkid and fbot but adds blockchain-based DNS resolution for server addresses. It spreads through weak Telnet/SSH credentials and known remote code execution vulnerabilities such as CVE-2025-9528 (Linksys E1700), CVE-2025-28137 (Totolink), CVE-2017-17215 (Huawei), and CVE-2020-8515 (DrayTek). Researchers estimate the botnet can launch DDoS attacks up to 4 Tbps in strength.