


Perceptive Security
SOC/SIEM Consultancy

New Dysphoria DDoS botnet spreads to 200k devices worldwide
Published:
27 juli 2026 om 21:08:15
Alert date:
27 juli 2026 om 22:00:55
Source:
bleepingcomputer.com
Mobile & IoT, Network Infrastructure, Ransomware & Malware
A new botnet named Dysphoria has compromised approximately 200,000 devices globally and is being used to conduct distributed denial-of-service (DDoS) attacks and traffic relay operations. The botnet has spread worldwide, indicating a large-scale and potentially well-organized threat campaign. The scale of infection suggests aggressive propagation mechanisms targeting internet-connected devices. DDoS botnets of this size pose significant risks to online services and infrastructure. The traffic relay functionality also suggests possible use for anonymizing malicious activity or proxying attacks. This represents an active and ongoing threat to both targeted organizations and the infected devices themselves.
Technical details
Mitigation steps:
Affected products:
Related links:
https://www.bleepingcomputer.com/news/security/aisuru-kimwolf-jackskid-and-mossad-botnets-disrupted-in-joint-action/
https://www.bleepingcomputer.com/news/security/new-botnet-hides-in-blockchain-dns-mist-and-removes-cryptominer/
https://blog.xlab.qianxin.com/dysphoria/
https://www.bleepingcomputer.com/news/security/critical-react2shell-flaw-exploited-in-ransomware-attacks/
https://www.bleepingcomputer.com/news/security/aisuru-botnet-sets-new-record-with-314-tbps-ddos-attack/
Related CVE's:
Related threat actors:
IOC's:
Ethereum ENS domains used for C2 resolution, Solana SNS domains used for C2 resolution, Fixed 78-byte login/heartbeat packets sent to C2, 155 UPnP port forwarding rules created on compromised devices, Fake IPv6 strings concealing C2 addresses
This article was created with the assistance of AI technology by Perceptive.
