New Dysphoria Botnet Compromises ~200 K IoT Devices for DDoS and Proxy Operations
What Happened — Researchers at QiAnXin XLab identified the Dysphoria botnet, an evolution of the “jackskid” and “fbot” families, actively controlling roughly 200 000 compromised routers, cameras, and other IoT endpoints. The botnet uses blockchain‑based ENS/SNS domains for C2, abuses UPnP to open 155 port‑forwarding rules, and spreads via weak Telnet/SSH credentials and several recent CVEs (e.g., CVE‑2025‑55182, CVE‑2025‑34152).
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a credential‑compromise and vulnerability‑management gap that SOC 2 access‑control criteria (CC6.1, CC6.2) are designed to detect and remediate.
- Continuous evidence collection on device hardening, privileged‑access reviews, and security‑awareness training provides the audit trail needed to demonstrate due diligence.
- Mapping these gaps to a SOC2 Access Controls capability helps organizations prove they have systematic processes for credential hygiene and vulnerability patching across all assets, including IoT.
Who Is Affected — Telecommunications, managed service providers, manufacturers, and any organization that relies on IoT/edge devices for operations.
Recommended Actions
- Inventory all network‑connected devices and classify them under your asset‑management program.
- Enforce strong, unique passwords for Telnet/SSH and disable unused services.
- Deploy automated vulnerability scanning for known IoT CVEs and integrate findings into your continuous‑monitoring pipeline.
- Document credential‑management controls and evidence of remediation for SOC 2 audit readiness.
Source: BleepingComputer
Technical Notes
- Botnet C2 resolves via Ethereum ENS and Solana SNS domains; payloads are hidden in crafted IPv6 strings.
- Exploited CVEs include CVE‑2025‑55182 (React2Shell), CVE‑2025‑34152, CVE‑2025‑28137 (Totolink), CVE‑2025‑9528 (Linksys), CVE‑2017‑17215 (Huawei), CVE‑2020‑8515 (DrayTek).
- Peak activity recorded 740 k daily pings, with claimed DDoS capacity up to 4 Tbps.