Skip to content
Rush Commerce
Field Notes3 min read

Dysphoria IoT botnet: your office camera is the recruit

The Dysphoria botnet spreads via weak Telnet and SSH passwords and old router flaws, and resolves its C2 through blockchain domains. Audit your edge gear.

The Dysphoria IoT botnet is not interesting because it is new. It's interesting because of how it recruits: weak Telnet and SSH passwords, and remote code execution flaws in routers, gateways, and cameras. That is a description of the hardware in most small offices — the gear that was installed once by somebody who no longer works there.

What actually happened

The Hacker News reports that Dysphoria emerged after law enforcement disrupted the JackSkid botnet on March 19, 2026, with the first Dysphoria sample documented six days later. It has since added encryption, victim machines relaying traffic to the real controllers, and UPnP-based port mapping to punch through NAT.

The C2 mechanism is the novel part. Instead of hardcoded servers, infected devices resolve controllers through blockchain naming — an Ethereum Name Service domain and a Solana Name Service domain — which makes takedown considerably harder than seizing a domain from a registrar. BleepingComputer covered the spread the same week.

On size: estimates from CNCERT and XLab put the botnet above 200,000 bots, with a single-day peak near 239,000 nodes outside China. Worth flagging that The Hacker News explicitly cautions none of these counts has been independently reproduced and they shouldn't be read as a precise device census. The infection method is well documented; the headcount is an estimate.

Why IoT botnet recruitment matters for your business

You are unlikely to be the target of a DDoS. You are quite likely to be the ammunition — and that has costs you actually feel. Conscripted devices burn your upstream bandwidth, get your IP ranges blocklisted, and hand an attacker a foothold inside your network that sits behind the firewall you spent money on.

The devices getting recruited share a profile: nobody owns them. The NVR the security installer set up in 2019. The ISP gateway with the sticker password still on it. The conference room display with an admin panel on port 80. None of it appears in an asset inventory because none of it feels like IT.

So build the list, then do four things. Kill Telnet — there is no 2026 reason for it to answer. Replace default and reused credentials on every device with a login, cameras and NVRs included. Turn off UPnP on the perimeter, since Dysphoria uses it for NAT traversal and almost nothing in a business network legitimately needs it. And check firmware against vendor advisories; the RCEs these botnets ride are frequently years old and long since patched, which means the exposure is a maintenance gap, not a zero-day.

Anything still unpatchable gets segmented onto its own VLAN with no path to your business systems, or gets replaced. Cameras are cheaper than incident response.

Key takeaways

  • Dysphoria spreads through weak Telnet/SSH credentials and known RCE flaws in routers, gateways, and cameras
  • It resolves command-and-control through ENS and SNS blockchain domains, making registrar-level takedown far harder
  • CNCERT and XLab estimate 200,000+ bots, but the counts are not independently verified — treat the method as the news, not the number
  • Disable Telnet, replace default credentials on every edge device, and turn off UPnP at the perimeter
  • Segment unpatchable or end-of-life devices onto an isolated VLAN, or replace them outright

Nobody has counted the devices on your network. We inventory what's actually plugged in — cameras, NVRs, gateways, displays — find the ones answering on the internet, and give you a segmentation plan you can hand to whoever maintains it. Book a network audit or see how we harden small-business infrastructure.

Sources: The Hacker News, BleepingComputer.

  • #dysphoria
  • #iot-security
  • #botnet
  • #network-hygiene
  • #ddos
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.