CVE-2025-9528
CVSS 4.7 MEDIUM: a vulnerability was determined in Linksys E1700 1.0.0.4.003. EPSS 54% (99th percentile).
Threats · 49 days ago
Dysphoria has moved the part defenders can see and block away from the real controller. A seizure or IP block now hits a relay or a naming record, not the endpoint the botnet actually depends on, so the usual takedown playbook loses leverage.
Researchers say the lineage added blockchain-based name services and infected-device relays after the March JackSkid disruption. XLab traced ENS and Solana name records, relay-only builds, and a design where bots ask a distribution node for a server list that points them to compromised machines relaying traffic onward; reported bot counts are large, but the counts are not independently verified.
That makes disruption harder, but not impossible. The chain still depends on blockchain records, reachable relays, and compromised devices, so defenders have to look past the obvious controller address and watch the full naming-and-relay layer.
CVSS 4.7 MEDIUM: a vulnerability was determined in Linksys E1700 1.0.0.4.003. EPSS 54% (99th percentile).
2 sources covering this story
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria adds blockchain C2 and victim relays after the JackSkid disruption, keeping controllers one step removed from addresses exposed to bots.
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.
Part of the PlainSec briefing for 2026-07-28