Dysphoria Botnet Hijacks Routers for DDoS and Proxy Relays

Brendan Smith
Brendan Smith - Cybersecurity Analyst
8 Min Read
A cracked router exposing rows of network ports chained into the Dysphoria botnet.
Dysphoria can turn vulnerable routers and embedded devices into DDoS workers or concealed network relays.

The Dysphoria botnet has grown to roughly 200,000 compromised devices, according to a joint technical report from QiAnXin XLab and CNCERT. The malware has evolved since late March 2026 from familiar IoT DDoS code into two roles: attack workers and infected relay nodes. Newer builds use Ethereum ENS and Solana SNS records to locate infrastructure, while a relay variant can ask a local gateway to create 155 UPnP port mappings.

The reported targets are mainly routers, gateways, cameras, and other embedded Linux devices exposed through weak Telnet or SSH credentials and known vulnerabilities. This is not evidence that every Windows PC behind the same router is infected. Device owners should inspect the network equipment first, then investigate computers separately only when endpoint alerts, unknown software, or suspicious traffic justify it.

Who should check for Dysphoria exposure

Situation Risk and what to check
Router, camera, or gateway still uses a default or reused administrator password Change it from a trusted local connection. Also review Telnet, SSH, and remote-management settings.
The device is internet-accessible or has not received firmware updates Identify the exact model and firmware. Apply the vendor’s current release or replace unsupported hardware.
The router shows many unknown port-forward or UPnP entries Record the entries, disconnect the suspicious device, and remove mappings that do not belong to known applications.
Bandwidth, DNS, or outbound traffic remains abnormal while normal computers are idle Compare traffic by device. A compromised IoT node may operate without files or antivirus alerts on a Windows PC.

XLab reported that Dysphoria spreads through weak Telnet and SSH credentials and a mix of old and recent remote-code-execution flaws. The affected list spans multiple router and IoT families rather than one vendor. An old device that cannot receive security fixes is therefore a larger concern than a supported model that is patched, locally managed, and protected by unique credentials.

How the botnet hides its command path

Earlier botnets often embedded a fixed IP address or ordinary domain in the malware. Dysphoria can instead read infrastructure data from blockchain name services. An ENS or SNS record supplies encoded information that the sample transforms into the next network location. Taking down one normal domain is less effective when the operator can update this distributed lookup path.

The newer architecture also separates roles. One build receives DDoS targets and timing parameters through a fixed 78-byte protocol. Another build drops the DDoS function and turns the infected host into a transparent relay. The relay sits between a worker and the real command infrastructure, making the final controller harder to trace and block.

This distinction matters to an owner: the device may be abused even when it is not generating an obvious traffic flood. A relay can consume bandwidth, expose services, damage the public IP address’s reputation, and hide someone else’s malicious traffic. The broader proxyjacking guide explains the same stolen-bandwidth problem outside this exact campaign.

Why 155 UPnP mappings are a serious clue

XLab observed a relay build that searches the local network for a UPnP-capable gateway and requests 155 port mappings. Those forwards expose listeners on the infected device to incoming internet connections. UPnP can be legitimate—game consoles, voice apps, and home services sometimes request it—but a sudden block of dozens or hundreds of unknown mappings is not normal household behavior.

One port-forward entry alone does not prove Dysphoria. Preserve the mapping list, identify which local IP requested it, and correlate it with the device model, firmware, DNS requests, and outbound traffic. Do not share live command addresses publicly or test suspicious services from the internet; that can destroy evidence or expose the network further.

What router and IoT owners should do now

  1. Inventory the device. Record the vendor, exact model, hardware revision, firmware version, local IP, and whether the vendor still provides security updates.
  2. Change administrative credentials. Replace default, weak, or reused passwords. Disable Telnet and password-based SSH when they are not required, and do not expose the management page to the internet.
  3. Review UPnP and port forwarding. Save a copy or screenshots of unexpected entries, identify the requesting device, then remove unauthorized mappings. Disable UPnP if no trusted application needs it.
  4. Apply firmware updates. Download firmware only from the vendor’s official support path. If the product is end-of-life or cannot be patched, replace it rather than leaving it publicly reachable.
  5. Reset only with a safe recovery plan. Obtain the patched firmware first, note the ISP connection settings, factory-reset the device, install the update, and create new credentials before reconnecting it. A reset without fixing the entry path can lead to reinfection.
  6. Separate IoT from sensitive systems. Put cameras, TV boxes, and other embedded devices on a guest or isolated network. The IoT security checklist covers segmentation and lifecycle risks.
  7. Check endpoints on their own evidence. If a Windows PC also shows unknown processes, downloads, security alerts, or blocked outbound traffic, disconnect and scan that PC separately. Gridinsoft Anti-Malware can check a Windows endpoint for detected malware and persistence, but it cannot scan or reflash router firmware.

The safest assumption is not that malware “jumped through Wi-Fi,” but that each exposed device needs its own evidence and remediation path. Our guide to malware and shared Wi-Fi explains when a common network creates risk without implying automatic infection of every connected computer.

FAQ

Does rebooting a router remove Dysphoria?

A reboot may interrupt malware that lives only in memory, but it does not patch the exploited flaw, remove weak credentials, or replace unsupported firmware. Rebooting without closing the entry path can allow the device to be compromised again.

Should I factory-reset every router because of this report?

No. First identify the model, firmware, exposure, port mappings, and vendor support status. Reset a suspicious device only when you can immediately install safe firmware and new credentials; replace an unsupported device.

Can Windows antivirus clean an infected router or camera?

No. Windows security software can check the PC, not reflash embedded-device firmware. Router or camera remediation depends on vendor updates, secure configuration, a controlled reset, or hardware replacement.

References

  1. Wang Hao; QiAnXin XLab and CNCERT. “Dysphoria Evolution and In-Depth Technical Analysis.” QiAnXin XLab, July 25, 2026. technical report.
  2. National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT). “Risk Notice on the Large-Scale Spread of the Dysphoria Botnet.” CNCERT, July 27, 2026. official risk notice.
  3. Cybersecurity and Infrastructure Security Agency. “Internet Exposure Reduction Guidance.” CISA, accessed July 28, 2026. exposure-reduction guidance.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?