Dysphoria Campaign Compromises 296,000 IoT Devices Worldwide

The Dysphoria malware operation has grown into a major IoT threat, with a new Shadowserver report identifying approximately 296,000 compromised devices.


The campaign targets internet-facing routers, gateways, IP cameras, DVRs, repeaters, and other embedded Linux systems. Compromised devices can be used for DDoS attacks, traffic relaying, and residential proxy operations.


Exposed IoT Devices Remain a Major Target

Dysphoria primarily takes advantage of devices that are often outside traditional endpoint-security programs.


Weak Credentials and Unpatched Systems Fuel Infections

Many consumer and small-business devices remain exposed to the internet for years, running outdated firmware or retaining weak credentials. Attackers have also exploited known remote-code-execution vulnerabilities affecting routers, cameras, gateways, and other embedded products.


Shadowserver's dataset identifies roughly 296,000 affected devices, giving network operators a substantial remediation target.
The organization classifies the reported infections as CRITICAL, as compromised systems can be remotely controlled for large-scale attacks, traffic relaying, or concealment of malicious infrastructure.


Blockchain Infrastructure Makes Tracking Harder

One of Dysphoria's notable characteristics is its use of blockchain-based naming services, including Ethereum Name Service and Solana Name Service, for command-and-control resolution.


Decentralized Naming Complicates Infrastructure Disruption

Unlike conventional domains that depend on traditional registrars and hosting providers, blockchain-based names can make infrastructure takedowns more difficult.


The malware combines this infrastructure with password attacks and exploitation of known vulnerabilities to silently recruit vulnerable systems.


Earlier observations placed the active botnet population above 200,000 devices, with researchers recording a single-day peak of approximately 239,000 bots outside the operators' primary region.


Infected Devices Can Become Proxy Nodes

Dysphoria has also evolved beyond conventional DDoS functionality.


Malware Can Abuse Residential Networks

A variant observed in late June reportedly removed its DDoS functionality and operated primarily as a proxy.


The malware scans local networks for UPnP-enabled gateways and attempts to create inbound access using router port mappings.

Researchers observed it opening port 155, allowing external traffic to pass through an infected system toward another destination.


This capability could enable attackers to hide malicious activity behind residential or small-business IP addresses, bypass restrictions, and obscure command-and-control infrastructure.


Shadowserver Data Helps Identify Infected Systems

The Shadowserver Special Report is intended to provide network defenders with detailed information about affected infrastructure.


Reports Include Valuable Exposure Details

The dataset can contain:


- IP address
- Port and protocol
- ASN
- Geographic information
- Device vendor and model
- Firmware version
- First and last observation times
- Exposure duration
- User agent
- Infection indicators


The report's distribution timestamp is August 12, 2026, while the last_seen_time field indicates the most recent observation associated with each IP address.


This information can help ISPs, CSIRTs, enterprises, and managed-service providers identify compromised equipment and prioritize remediation.


Defenders Should Secure Exposed Devices

Organizations and network operators should immediately investigate systems associated with Dysphoria indicators.


Recommended Remediation Steps

Defensive actions include isolating suspected devices, changing administrative and Telnet/SSH credentials, disabling unnecessary remote administration and UPnP, installing available firmware updates, and replacing unsupported hardware.


Teams should also review port-forwarding configurations, investigate unexplained outbound connections, and look for evidence that devices are being used as traffic relays.


Dysphoria Raises the IoT Threat Level

Dysphoria demonstrates how compromised edge devices can provide attackers with capabilities far beyond traditional DDoS infrastructure.


Every Unpatched Device Can Become an Attacker Asset

Its combination of large-scale recruitment, decentralized command infrastructure, and proxy capabilities turns vulnerable routers, cameras, and gateways into valuable criminal infrastructure.


For defenders, securing internet-facing IoT equipment is therefore no longer simply about preventing DDoS participation. It is also about preventing compromised devices from becoming anonymous relay points for broader cyberattacks.