Security · 1h ago
Dysphoria Botnet Infects 200K Devices via Blockchain DNS and UPnP Relays
A new botnet called Dysphoria has compromised 200,000 IoT and Linux devices using weak credentials and 13 known vulnerabilities. It uses Ethereum Name Service and Solana Name Service to resolve multi-stage C2 servers, and exploits UPnP to turn infected devices into relays. The malware hides as libdalvikengine.so and can launch DDoS attacks on command.
Meridian48 take
The use of blockchain name resolution makes takedowns harder, but the reliance on weak passwords and old CVEs means basic hygiene still stops most infections.
Read the full reporting
Dysphoria: A 200k-Device Botnet Using Blockchain Name Resolution and Infected Device Relays →
DEV Community
botnetblockchain-dns