Dysphoria Botnet Leverages 296,000 IoT Devices for DDoS and Proxy Services
The Dysphoria botnet has weaponized approximately 296,000 compromised routers and cameras, transforming them into bots for distributed denial-of-service (DDoS) attacks and command-and-control (C2) relay nodes, while also adding residential proxy functionality.

The Dysphoria botnet has significantly expanded its reach, compromising an estimated 296,000 internet-connected devices, including routers, security cameras, and gateways. These devices are now being leveraged to launch distributed denial-of-service (DDoS) attacks and serve as command-and-control (C2) relay nodes for malicious activities. The sheer volume of compromised devices, often situated in homes and small businesses, presents a substantial threat, capable of overwhelming online services and making them inaccessible.
Beyond its DDoS capabilities, Dysphoria has recently incorporated residential proxy functionality. This addition allows attackers to route their own malicious traffic through the compromised devices, effectively masking their origin and making it considerably more challenging to trace the source of illicit activities. Shadowserver, a cybersecurity monitoring organization, identified this escalating threat and detailed its findings in a special report, highlighting the dual risks posed by exposed IoT equipment.
The botnet primarily targets Internet of Things (IoT) devices, a broad category encompassing a wide array of connected hardware. By compromising these devices, attackers create a botnet – a network of infected machines under their control. Each device can then await and execute instructions, contributing its processing power and network bandwidth to coordinated attacks. The use of seemingly legitimate residential connections for attack traffic complicates mitigation efforts for targeted services.
This operational model is not unique, as other campaigns have similarly repurposed consumer-grade equipment for malicious purposes, such as the AryStinger router proxy network. However, Dysphoria's reported scale and its sophisticated proxy capability enhance the value and impact of each compromised device, turning them into versatile tools for cybercriminals.
Shadowserver's analysis classifies the observed events as critical, providing detailed information on affected IP addresses, ports, protocols, locations, and, where available, device vendor and model. The report does not pinpoint a single exploit or vulnerability responsible for the widespread compromises, suggesting a multi-faceted approach by the attackers. This underscores the need for comprehensive security measures rather than relying on a single fix.
The integration of residential proxy services elevates the threat posed by Dysphoria from mere disruption to sophisticated concealment. Attackers can now leverage these compromised devices to mask their own network traffic, making it appear as though malicious actions originate from ordinary household or small-office internet connections. This tactic has become a growing concern in the landscape of threats involving consumer hardware.
Security experts recommend several key actions for mitigating the risks associated with botnets like Dysphoria. These include regularly updating device firmware, replacing default and weak administrator passwords, disabling remote administration unless absolutely necessary, and segmenting IoT devices onto separate networks. For organizations managing fleets of connected equipment, a thorough review of externally exposed management services is paramount.
Ultimately, the Dysphoria botnet serves as a stark reminder that routers, cameras, and other connected devices are not merely passive appliances. When connected to the internet and left unmanaged or inadequately secured, they become potent tools for cybercriminals, capable of facilitating widespread outages and enabling anonymity for malicious actors. Prompt remediation and ongoing vigilance are crucial for protecting both individual users and the broader internet ecosystem.