Overview
- Between July 14 and 20 researchers from QiAnXin XLab and CNCERT recorded active-device telemetry and peaks that they used to estimate roughly 200,000 infected IoT devices, but the published counts lack a documented counting and de-duplication method and have not been independently reproduced.
- The malware resolves command information from Ethereum ENS and Solana SNS name records, encodes controller addresses in fake IPv6 formats, and uses a byte-transformation algorithm to recover C2 endpoints so operators do not expose direct server IPs.
- A relay-only variant observed on June 25 drops DDoS code and uses UPnP port mapping plus Linux epoll to turn compromised routers and gateways into proxies that shuttle traffic between outside clients and hidden controllers.
- Dysphoria spreads by guessing weak Telnet and SSH credentials and by exploiting known IoT remote‑code‑execution flaws, including Linksys CVE-2025-9528 and several 2025-era vulnerabilities as well as older unpatched defects in routers and cameras.
- Operators advertise up to about 4 Tbps on a storefront but researchers have reported no independently measured Dysphoria attack peak; defenders can still disrupt the botnet by patching devices, removing default passwords, disabling UPnP and remote management, and coordinating takedowns of distribution nodes and relays.