A Special Report has identified approximately 296,000 internet-connected devices compromised by the Dysphoria botnet, marking an expansion of an IoT threat already linked to distributed denial-of-service attacks and residential proxy operations. The report categorizes all listed events as critical, offering affected-network operators with retrospective data for identifying and remedying exposed devices. Dysphoria primarily targets internet-facing IoT systems, including routers, cameras, gateways, DVRs, and other embedded Linux devices.
Earlier variants focused on creating a DDoS-capable botnet, while newer versions also convert victims into relay infrastructure capable of carrying attacker-controlled traffic.
They can act both as attack participants and as a source of seemingly residential or small-business network traffic, enabling malicious actors to conceal their origins, bypass IP restrictions, engage in automated abuse, or route through legitimate broadband connections. In contrast, Dysphoria supports DDoS operations alongside a distributed proxy layer across compromised networks. The new relay capability is particularly noteworthy due to its ability to make a compromised device useful even when it's behind network address translation (NAT).
Researchers reported that Dysphoria abuses Universal Plug and Play (UPnP) to create port-forwarding rules, potentially mapping up to 155 ports. This blockchain-based method makes it harder for attackers to disrupt operations, as defenders cannot solely focus on blocking a limited number of conventional domains or IP addresses.












