Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Dysphoria Botnet Hides Command Servers Using Ethereum and Solana Domains

Dysphoria Botnet Hides Command Servers Using Ethereum and Solana Domains

Researchers Identify 200,000-Device Malware Network

Kelly Cromley by Kelly Cromley
Jul 29, 2026
in Ethereum News, Market News, News, Solana News
Reading Time: 3 mins read
0
Malware

Cybersecurity researchers have identified a sophisticated botnet known as Dysphoria that has compromised approximately 200,000 devices worldwide and employs blockchain-based domain names on the Ethereum and Solana networks to conceal its command-and-control (C2) infrastructure. The findings were jointly disclosed by QiAnXin XLab and China’s National Computer Network Emergency Response Technical Team/Coordination Center (CNCERT), highlighting the malware’s rapid technical evolution and increasing sophistication.

Ethereum and Solana Domains Used to Conceal Command Infrastructure

According to the researchers, Dysphoria has evolved from the earlier jackskid and fbot malware families. Since it was first detected by QiAnXin XLab in March 2026, the botnet has undergone multiple upgrades in only a few months, incorporating stronger encryption techniques, blockchain-based command server discovery, and a specialized relay variant that transforms compromised systems into covert proxy nodes.

Researchers reported that Dysphoria has infected around 200,000 devices globally and now uses Ethereum Name Service (ENS) and Solana Name Service (SNS) domains to conceal its command-and-control infrastructure, making detection significantly more difficult.

QiAnXin XLab stated that it had been tracking Dysphoria since the first quarter of 2026 and observed frequent mutations and technological enhancements during that period. The researchers indicated that the malware demonstrated considerable resilience through continuous development, evolving across multiple variants while introducing blockchain-based command resolution and expanding its functionality by converting infected devices into relay nodes.

One of the most significant technical developments involves the malware’s command server resolution mechanism. Instead of embedding command server addresses directly into the malicious code or relying on conventional domain name services, Dysphoria queries Ethereum Name Service domains such as burrberry.eth and ukranianhorseriding.eth, along with a Solana Name Service domain. These domains contain specially crafted TXT records that appear to store IPv6 addresses but actually conceal the real Internet Protocol addresses through a customized byte transformation process. As a result, the malware avoids exposing the actual server locations in either its code or standard network traffic.

The report also highlighted substantial changes to the malware’s encryption techniques. Dysphoria incorporates a heavily modified implementation of the RC4 encryption algorithm, introducing additional processing stages beyond the standard design. Researchers explained that the malware combines a Linear Congruential Generator (LCG) with repeated S-box shuffling and a Linear Feedback Shift Register (LFSR) during keystream generation, making encrypted strings significantly more difficult to analyze through conventional malware inspection methods. Consequently, standard string-scanning tools produce little useful information for security analysts.

The latest Dysphoria variants combine customized RC4 encryption with blockchain-based command resolution and encrypted string protection, substantially increasing resistance to malware analysis and infrastructure detection.

Researchers also identified a new relay-focused variant that emerged on June 25. Unlike previous versions that contained distributed denial-of-service (DDoS) attack modules, the updated variant primarily converts infected devices into hidden relay servers. After compromising a system, the malware discovers the local network gateway through Universal Plug and Play (UPnP) requests and automatically establishes as many as 155 port-forwarding rules.

The relay architecture enables compromised devices to transparently forward network traffic between attackers and remote command servers using Linux’s high-performance asynchronous input/output framework. Researchers explained that each relay node periodically sends status reports containing connection statistics and bandwidth information to a centralized heartbeat server every four seconds. This design prevents DDoS bots from communicating directly with the actual command servers, instead routing traffic through other infected systems that function as intermediary relays.

Monitoring conducted between July 14 and July 20 recorded peak daily communication volumes of approximately 740,000 pings from infected hosts. During that period, researchers observed as many as 239,000 active overseas devices and 1,801 active devices within China on a single day, indicating the botnet’s substantial global footprint.

The investigation also revealed that Dysphoria spreads by exploiting weak Telnet and Secure Shell (SSH) credentials, as well as numerous known vulnerabilities affecting routers, surveillance cameras, and Internet of Things (IoT) devices. The malware targets both recently disclosed vulnerabilities and older flaws that remain unpatched across many deployed systems.

Researchers further reported that Dysphoria operators advertise DDoS-for-hire services capable of delivering up to 4 terabits per second of attack capacity while maintaining nearly continuous attacks against organizations across multiple industries worldwide.

The report concluded that Dysphoria represents an increasingly mature cybercriminal operation whose combination of blockchain technology, advanced encryption, relay-based infrastructure, and aggressive propagation techniques presents a growing challenge for cybersecurity defenders seeking to identify and disrupt its global operations.

 

Previous Post

Tether and Nairobi Exchange Advance Blockchain Market Infrastructure

Next Post

European Banks Launch RL1 Blockchain Payment Network

Related Posts

regulated layer one - RL1

European Banks Launch RL1 Blockchain Payment Network

by Kelly Cromley
Jul 29, 2026
0

A consortium of leading European financial institutions has launched Regulated Layer 1 (RL1), a blockchain network designed to provide a...

Kenya

Tether and Nairobi Exchange Advance Blockchain Market Infrastructure

by Kelly Cromley
Jul 29, 2026
0

Kenya’s Nairobi Securities Exchange (NSE) has signed a Memorandum of Understanding (MoU) with stablecoin issuer Tether to explore the adoption...

clearpool

Clearpool Launches Trade Finance Vault With 15% USDC Target

by Kelly Cromley
Jul 29, 2026
0

Clearpool has launched a new trade finance vault in partnership with Tradevu, with portfolio management provided by Cicada Credit, expanding...

Philippines

Philippines SEC Launches Blockchain-Based VERITAS for Digital Filings

by Kelly Cromley
Jul 29, 2026
0

The Securities and Exchange Commission (SEC) of the Philippines has introduced new regulations allowing companies and other registered entities to...

Trust Wallet

Trust Wallet Adds WalletConnect Support for Tron dApps

by Kelly Cromley
Jul 29, 2026
0

Trust Wallet has expanded its blockchain compatibility by introducing WalletConnect support for the Tron network, allowing users to directly connect...

txflow

TxFlow_L1 and Onchain Lens Launch Early Access Trading Campaign

by Kelly Cromley
Jul 29, 2026
0

Onchain Lens has entered into a partnership with TxFlow_L1, a newly launched Layer 1 blockchain focused on financial execution. The...

Next Post
regulated layer one - RL1

European Banks Launch RL1 Blockchain Payment Network

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

regulated layer one - RL1
Market News

European Banks Launch RL1 Blockchain Payment Network

by Kelly Cromley
Jul 29, 2026
Malware
Ethereum News

Dysphoria Botnet Hides Command Servers Using Ethereum and Solana Domains

by Kelly Cromley
Jul 29, 2026
Kenya
Market News

Tether and Nairobi Exchange Advance Blockchain Market Infrastructure

by Kelly Cromley
Jul 29, 2026
clearpool
Market News

Clearpool Launches Trade Finance Vault With 15% USDC Target

by Kelly Cromley
Jul 29, 2026
Philippines
Market News

Philippines SEC Launches Blockchain-Based VERITAS for Digital Filings

by Kelly Cromley
Jul 29, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.