Dysphoria Botnet Infects 200,000 Devices with Blockchain Domain Names
A rapidly evolving botnet called Dysphoria has infected approximately 200,000 devices worldwide and adopted blockchain-based domain names to hide its command-and-control infrastructure.
Researchers at QiAnXin XLab and China's national computer emergency response team CNCERT disclosed the threat in late July 2026 after tracking its aggressive technical evolution since March.
Dysphoria's use of Ethereum and Solana blockchain domains represents a meaningful escalation in how malware operators can evade traditional takedown methods.
The botnet queries blockchain-based name services to retrieve command details from decentralized records, making it harder for defenders to disrupt the infrastructure.