A rapidly evolving Internet of Things (IoT) botnet named Dysphoria has compromised approximately 200,000 devices globally, including routers, cameras, and gateways. This malware exploits weak Telnet and SSH passwords, as well as known software vulnerabilities, to infiltrate systems. Despite the prevalence of such attack vectors, many IoT devices remain vulnerable due to outdated firmware and poor security practices.
Innovative Use of Blockchain for Command and Control
One of Dysphoria’s distinguishing features is its utilization of blockchain-based domains to obscure its command-and-control (C2) infrastructure. By leveraging Ethereum Name Service (ENS) and Solana Name Service (SNS) domains, the malware dynamically retrieves network information, allowing operators to update C2 servers without modifying each infected device. This method enhances the botnet’s resilience against traditional domain or IP address blocking techniques.
Expansion into Relay Networks
Recent variants of Dysphoria have shifted focus from Distributed Denial-of-Service (DDoS) attacks to establishing relay proxies. These versions identify network gateways supporting Universal Plug and Play (UPnP) to open ports and expose infected devices for traffic relaying. Consequently, compromised devices can serve as intermediaries, routing external traffic to remote destinations, thereby complicating efforts to trace malicious activities back to their origin.
Security researchers observed that between July 14 and July 20, there were 4,401 active bots in China, with the peak number of overseas bots reaching 239,000. Leaked control-panel screenshots suggest that Dysphoria’s operators maintain a botnet of around 200,000 devices, boasting a potential DDoS capacity of up to 4 Tbps.
To mitigate the risk of infection, device owners are advised to change default credentials, disable unnecessary remote management features, and apply firmware updates promptly. Organizations should also segment IoT devices from critical networks to limit potential damage from compromised systems.
The emergence of Dysphoria underscores the persistent threat posed by IoT botnets and the innovative tactics employed by cybercriminals to evade detection. The use of blockchain domains for C2 communication represents a significant evolution in malware design, highlighting the need for continuous adaptation in cybersecurity defenses. As IoT devices become increasingly integrated into daily life, ensuring their security is paramount to prevent large-scale cyberattacks.