A new botnet, known as Dysphoria, has recently caught the attention of researchers with its ability to compromise 200,000 connected devices worldwide. Using sophisticated techniques, this botnet relies on the blockchain to hide its command servers and thus evade monitoring efforts. This article explores the methods employed by Dysphoria to extend its influence and the risks it poses to users of connected devices.
A growing threat: 200,000 compromised devices
Identified in the first quarter of 2026 by researchers at QiAnXin XLab, the Dysphoria botnet primarily focuses on connected devices, particularly routers and surveillance cameras. The report established by the researchers highlights the rapid expansion of this botnet, which has seen its capabilities grow through frequent updates of its technical variants. The resilience of Dysphoria raises concerns about the security of connected devices.
Infiltration techniques: targeted attacks
To penetrate these devices, Dysphoria employs a combination of proven strategies. The botnet typically starts by testing a wide range of common or default passwords, taking advantage of users who do not change their device security credentials. Concurrently, it exploits known vulnerabilities, including those affecting popular routers such as the Linksys E1700, allowing for rapid and effective control of targeted devices.
Exploitation of compromised devices
Once a device is compromised, it becomes a component of the botnet and is primarily used to launch DDoS attacks. These attacks aim to flood servers with requests, rendering websites or services inaccessible. Dysphoria is notable for its ability to generate a strike force of up to 4 terabits per second, an achievement that positions it among the most powerful botnets currently in existence.
Hiding operations: the innovative use of blockchain
Dysphoria adopts a unique approach compared to other botnets by using the blockchain to conceal its operations. Unlike traditional criminal networks that rely on fixed domains or IP addresses, Dysphoria turns to decentralized naming services, such as the Ethereum Name Service (ENS) and the Solana Name Service (SNS). As a result, infected devices retrieve the addresses of their command servers through blockchain-related domain names, making their traceability much more difficult.
Bypassing security systems
To further complicate detection, Dysphoria uses altered IPv6 addresses, allowing it to conceal the transmission of instructions to the botnet. Monitoring systems, often configured to detect suspicious IP addresses, encounter hurdles when attempting to identify this type of communication. With this approach, Dysphoria illustrates how malicious actors can exploit modern technologies to operate undetected.
The landscape of cyber threats
This use of blockchain is not limited to Dysphoria. Other groups of cybercriminals, such as certain North Korean hackers, have also begun to mask their operations by integrating malicious scripts into smart contracts on the blockchain. This evolution in the realm of cyber threats presents new challenges for security, rendering traditional detection systems obsolete and highlighting the need for increased vigilance against these new risks.
To learn more about the implications of this botnet and other similar threats, check out this in-depth analysis.







