The home router can look perfectly serviceable, give away Wi-Fi and stand on the shelf for years while other people's attacks pass through it. Researchers found about 296,000 devices infected with the Dysphoria botnet. The network got routers, gateways, IP cameras and other Linux-based equipment that attackers use for DDoS attacks and as hidden proxy servers.
The new data was published by Shadowserver Foundation, which assigned all detected cases of infection the maximum level of danger CRITICAL. The scale was noticeably higher than previous estimates. At the end of July, XLab and CNCERT specialists reported more than 200 thousand devices under the control of Dysphoria, and the number of simultaneously active infected devices outside China on some days reached 239 thousand.
Dysphoria is spreading in a fairly traditional way for IoT botnets. The malware moves weak passwords to Telnet and SSH, and also exploits known remote code execution vulnerabilities. Among the targets are home and office routers, network gateways, cameras and other devices that often work for years with old firmware and Internet-accessible control interfaces. The researchers found in the arsenal of Dysphoria both old vulnerabilities that botnets have been using for many years, and errors discovered relatively recently.
The main feature of Dysphoria is not so much with the number of infected devices, but with the device of the control infrastructure. Instead of the usual domains, the creators of the botnet used Ethereum Name Service and Solana Name Service. Through ENS and SNS records, the malware receives the infrastructure addresses needed for communication. This approach complicates the shutdown of the botnet, since defenders cannot simply achieve the blocking of a conventional domain from the registrar.
Dysphoria operators have added another level of masking. Infected devices can operate intermediate nodes between bots and real control servers. When analyzing network traffic, the researcher sees the address of someone else’s infected device, not the real server of the botnet operators. This scheme significantly complicates the search and blocking of infrastructure.
At the end of June, the developers went further. The researchers found a separate version of Dysphoria, which did not have the functions of DDoS attacks at all. The only task of the infected device was to work as a proxy and repeater. A few days later, there was an automatic configuration of ports with UPnP, allowing the malware to bypass NAT restrictions and receive external connections.
As a result, the usual home IP address can be used as an intermediate point for someone else’s traffic. The attacker is able to hide the real source of the connection, bypass the restrictions on IP addresses or hide the control servers behind the networks of unsuspecting device owners. Thus, Dysphoria is gradually transformed from a classic DDoS botnet into a distributed infrastructure from home proxy servers.
The commercial component of the project is also present. On the page, which the researchers associate with Dysphoria, operators stated the power of DDoS attacks up to 4 Tbps and offered toll tariffs, the cost of which depended on the duration and capacity of the attack. XLab observed attacks almost daily, and among the targets there were Internet services and game projects in different countries.
Shadowserver recommends that owners and administrators of potentially affected devices update firmware, change administrative passwords and Telnet and SSH credentials, disable unnecessary remote access and UPnP, and check ports. Old devices, for which the manufacturer no longer releases security updates, are better replaced.
The new data was published by Shadowserver Foundation, which assigned all detected cases of infection the maximum level of danger CRITICAL. The scale was noticeably higher than previous estimates. At the end of July, XLab and CNCERT specialists reported more than 200 thousand devices under the control of Dysphoria, and the number of simultaneously active infected devices outside China on some days reached 239 thousand.
Dysphoria is spreading in a fairly traditional way for IoT botnets. The malware moves weak passwords to Telnet and SSH, and also exploits known remote code execution vulnerabilities. Among the targets are home and office routers, network gateways, cameras and other devices that often work for years with old firmware and Internet-accessible control interfaces. The researchers found in the arsenal of Dysphoria both old vulnerabilities that botnets have been using for many years, and errors discovered relatively recently.
The main feature of Dysphoria is not so much with the number of infected devices, but with the device of the control infrastructure. Instead of the usual domains, the creators of the botnet used Ethereum Name Service and Solana Name Service. Through ENS and SNS records, the malware receives the infrastructure addresses needed for communication. This approach complicates the shutdown of the botnet, since defenders cannot simply achieve the blocking of a conventional domain from the registrar.
Dysphoria operators have added another level of masking. Infected devices can operate intermediate nodes between bots and real control servers. When analyzing network traffic, the researcher sees the address of someone else’s infected device, not the real server of the botnet operators. This scheme significantly complicates the search and blocking of infrastructure.
At the end of June, the developers went further. The researchers found a separate version of Dysphoria, which did not have the functions of DDoS attacks at all. The only task of the infected device was to work as a proxy and repeater. A few days later, there was an automatic configuration of ports with UPnP, allowing the malware to bypass NAT restrictions and receive external connections.
As a result, the usual home IP address can be used as an intermediate point for someone else’s traffic. The attacker is able to hide the real source of the connection, bypass the restrictions on IP addresses or hide the control servers behind the networks of unsuspecting device owners. Thus, Dysphoria is gradually transformed from a classic DDoS botnet into a distributed infrastructure from home proxy servers.
The commercial component of the project is also present. On the page, which the researchers associate with Dysphoria, operators stated the power of DDoS attacks up to 4 Tbps and offered toll tariffs, the cost of which depended on the duration and capacity of the attack. XLab observed attacks almost daily, and among the targets there were Internet services and game projects in different countries.
Shadowserver recommends that owners and administrators of potentially affected devices update firmware, change administrative passwords and Telnet and SSH credentials, disable unnecessary remote access and UPnP, and check ports. Old devices, for which the manufacturer no longer releases security updates, are better replaced.