Find notable cyber news and cases, enriched with sources, timelines, and signals.

Dysphoria botnet DDoS and traffic relay activity

Malware Activity
First reported
Last updated
Happening score
H score 83
1 unique sources, 1 articles

Summary

Hide ▲

The Dysphoria botnet has grown to around 200,000 infected devices and is being used for DDoS attacks and traffic relay, expanding its disruption potential. Security researchers have tracked the family since Q1 2026 and say it evolved from jackskid and fbot. Its operators use a blockchain-based C2 built on Ethereum ENS and Solana SNS, with hidden addresses recovered from fake IPv6 strings. A late-June variant dropped DDoS behavior and focused on proxying, while July 14-20 monitoring showed sustained botnet activity.

Related Happenings

AryStinger botnet turns outdated routers into proxy executors

Malware Activity
H score60 First: 21.06.2026 17:14 Last: 21.06.2026 17:14 Sources 1

About this happening: The AryStinger botnet is compromising more than 4,000 outdated routers and converting them into proxy executors for malicious traffic, expanding attacker reach and int...

AVRecon malware for Linux powering SocksEscort proxy network

Malware Activity
H score19 First: 12.03.2026 18:19 Last: 12.03.2026 18:19 Sources 1

About this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...

AISURU/Kimwolf hyper-volumetric DDoS botnet activity

Malware Activity
H score23 First: 05.02.2026 19:25 Last: 05.02.2026 19:25 Sources 1

About this happening: The AISURU/Kimwolf botnet is a malware activity cluster tied to hyper-volumetric DDoS attacks and large-scale device conscription. On 2025-12-04, Cloudflare said i...

Latest development: 20.03.2026 08:25

The U.S. Department of Justice disrupted command-and-control infrastructure used by AISURU, Kimwolf, JackSkid, and Mossad in a court-authorized law-enforcement operation, with support from Akamai, Amazon Web Services, Cloudflare, DigitalOcean, Google, Lumen, Nokia, Okta, Oracle, PayPal, SpyCloud, Synthient, Team Cymru, Unit 221B, and QiAnXin XLab.

Aisuru/Kimwolf botnet record DDoS campaign against telecommunications and IT companies

Campaign
H score60 First: 29.01.2026 16:55 Last: 29.01.2026 16:55 Sources 1

About this happening: The Aisuru/Kimwolf botnet campaign expanded in late 2025 with Kimwolf, a DDoS botnet compiled using the NDK, and evidence linking it to AISURU through shar...

Latest development: 20.03.2026 02:49

The U.S. Justice Department, with authorities in Canada and Germany, dismantled infrastructure behind Aisuru, Kimwolf, JackSkid and Mossad, seized U.S.-registered domains and virtual servers used in DDoS attacks against DoD Internet addresses, and said the action was intended to prevent further infections and future attacks.

Kimwolf botnet infects Android TV streaming boxes for DDoS and proxy abuse

Malware Activity
H score16 First: 09.01.2026 01:23 Last: 09.01.2026 01:23 Sources 1

About this happening: Kimwolf/Aisuru botnet activity now spans Android TV streaming devices and record-setting DDoS attacks. Cloudflare says the latest campaign, “The Night Before Christm...

Latest development: 20.03.2026 10:05

Authorities from the United States, Germany, and Canada disrupted Command and Control (C2) infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets to infect Internet of Things (IoT) devices and launch hundreds of thousands of DDoS attacks, including attacks against IP addresses owned by the Department of Defense Information Network (DoDIN).

Timeline

  1. 28.07.2026 00:08 2 articles · 2h ago

    Dysphoria botnet compromises around 200,000 devices worldwide

    Initial Disclosure

    QiAnXin XLab says the Dysphoria botnet has compromised around 200,000 devices worldwide and is being used for DDoS attacks and traffic relay operations. The family, tracked since Q1 2026, evolved from jackskid and fbot by adding a covert blockchain-based C2 resolution mechanism using Ethereum ENS and Solana SNS, and researchers first spotted it on March 25. XLab also observed a late-June variant that focused on network proxying and dropped DDoS functionality, then monitored the botnet between July 14 and 20, recording a peak of 740,000 daily pings from infected hosts. The malware spreads through weak Telnet and SSH credentials and known vulnerabilities in routers, cameras, and various IoT devices, and it abuses UPnP to create 155 port forwarding rules on compromised devices.

    Show sources