Affected Systems
Approximately 200,000 routers, cameras, and IoT devices worldwide. Targets include devices with weak Telnet/SSH credentials and known vulnerabilities: CVE-2025-55182 (React2Shell), CVE-2025-34152, CVE-2025-28137 (Totolink), CVE-2025-9528 (Linksys), CVE-2017-17215 (Huawei), CVE-2020-8515 (DrayTek). A proxy-focused variant abuses UPnP to create 155 port forwarding rules on compromised devices.
Exploitation Status
Active exploitation confirmed. Dysphoria has been spreading since at least March 2026, with multiple variants observed. The botnet operators advertise DDoS-for-hire services on a clearnet website claiming 4 Tbps capacity. XLab recorded 740,000 daily pings from infected hosts during July 14-20, 2026.
Business Impact
Organizations face dual threats: outbound DDoS participation and unauthorized proxy relay operations. The proxy variant creates 155 UPnP port forwarding rules, exposing internal services to the internet and enabling abuse for anonymization or lateral movement. Infected devices generate significant C2 traffic (78-byte heartbeat packets). The botnet's blockchain-based C2 (Ethereum ENS, Solana SNS) complicates takedown efforts. Organizations with vulnerable IoT devices, routers, or cameras risk becoming unwitting attack infrastructure.
Urgency
🔴 Immediate
Recommended Actions
- Audit and patch routers, cameras, and IoT devices for CVE-2025-55182, CVE-2025-34152, CVE-2025-28137, CVE-2025-9528, CVE-2017-17215, and CVE-2020-8515 immediately
- Disable UPnP on all routers and IoT devices; monitor firewall logs for unexpected port forwarding rules (155 rules is a strong indicator)
- Enforce strong, unique credentials on all Telnet and SSH services; disable Telnet where possible and restrict SSH to known IP ranges
- Monitor network traffic for 78-byte fixed-length packets to external IPs and DNS queries to Ethereum ENS (.eth) or Solana SNS (.sol) domains
- Disable remote management interfaces on IoT devices unless operationally required; segment IoT devices on isolated VLANs with egress filtering
