Since the first quarter of 2026, cybersecurity researchers at XLAB have been monitoring an increasing botnet family known as Dysphoria. The group’s most recent development is particularly alarming; it includes a dedicated relay variant that turns infected routers, gateways, cameras, and embedded Linux devices into externally accessible proxy nodes. This makes it more challenging to disrupt because the Command & Control (C2) layer is spread across a wider range of compromised residential and IoT devices rather than being confined to just a few servers.

Dysphoria has evolved into several variants, including Jackskid and Fbot-derived samples. Initial activity in late March targeted Ethereum Name Service (ENS) domain m3rnbvs5d.eth, while later versions switched to ENS and Solana Name Service (SNS) domains for locating C2 infrastructure.

The implementation combines standard RC4 operations with a linear congruential generator and a linear feedback shift register, making static configuration extraction more challenging for analysts. The malware listens on these ports and uses Linux epoll-based non-blocking I/O to relay traffic between an external connection and a remote C2 service using the same port number as stated by qianxin. The relay periodically sends health reports to login.trees4sale.net:9000, including node availability, connection counts, and bandwidth details, enabling operators to pinpoint active proxy systems.

Utilize ANY.RUN for SOC investigations to avoid blind spots, detect threats earlier, and minimize response costs and business disruptions.