Incident QiAnXin XLab ddos-botnet ics-ot-iot
DDoS-ботнет Dysphoria заразил более 200 000 устройств по всему миру
CVE Tools coverage
Security researchers from QiAnXin XLab and China's CNCERT have identified a new IoT botnet named Dysphoria, which has already infected over 200,000 devices globally. The malware leverages Ethereum and Solana blockchain name services to obscure its command-and-control infrastructure, making detection and takedown more difficult. Dysphoria builds on previous threats like JackSkid and fbot but adds blockchain-based DNS resolution for server addresses. It spreads through weak Telnet/SSH credentials and known remote code execution vulnerabilities such as CVE-2025-9528 (Linksys E1700), CVE-2025-28137 (Totolink), CVE-2017-17215 (Huawei), and CVE-2020-8515 (DrayTek). Researchers estimate the botnet can launch DDoS attacks up to 4 Tbps in strength.