About 200,000 devices. Not a named bank. Not a 12.4 Tbps Cloudflare banner. QiAnXin XLab's Dysphoria research, summarized by BleepingComputer on July 27, is quieter than that: an IoT worm descended from jackskid and fbot that resolves command-and-control through Ethereum Name Service and Solana Name Service, then hides C2 addresses inside fake IPv6 strings unpacked with a custom byte transform. First seen March 25. Since then multi-chain support, new domains, and a fork between relay-focused and DDoS-focused builds. The point of the blockchain layer isn't mystique. It's making takedown expensive.
78-byte heartbeats and a late-June proxy fork
Infected clients, per XLab via BleepingComputer, send a fixed 78-byte login/heartbeat, then get attack commands encoding duration, type, targets, flags. Classic botnet loop. Modern discovery in front. ENS/SNS live on public chains, registrar abuse desks don't yank those pointers the way they yank a GoDaddy name. Fake-IPv6 concealment adds a decode step before anyone maps controllers from a pcap alone. It's not elegant malware. It's stubborn malware.
July 14–20 monitoring: peak 740,000 daily pings, ~239,000 overseas connections, ~1,800 from China. Pings ≠ unique devices. XLab still pegs the population around 200,000, close enough to operator panel screenshots on social media that the lab treats those shots as corroboration, not pure theater. I always squint at panel screenshots, they can be staged, but when they line up with independent telemetry, the shrug gets smaller.
Late June: a variant that dumped DDoS modules and turned victims into proxies. UPnP abuse creates 155 port-forwarding rules, exposing internal services inbound. Different business than volumetric floods. Knock down one front end and traffic still hairpins through someone else's living-room router. Split builds also let operators sell capabilities separately and complicate signature cleanup. Hunt only for flood tooling and you'll miss the quiet proxies holding the control plane up.
2017 passwords, 2025 RCEs, marketing terabits
Spread still leans on weak Telnet/SSH plus known IoT flaws. Recent list: React2Shell CVE-2025-55182, CVE-2025-34152, Totolink CVE-2025-28137, Linksys CVE-2025-9528. Older holes stay in rotation, Huawei CVE-2017-17215, DrayTek CVE-2020-8515. 2017 firmware sins next to 2025 app RCEs is how botnets stay fat. Consumer and SMB edge patch cadence is still measured in years. No novel zero-day narrative required, just port 23 answering admin/admin and vendors whose long-tail gear never sees a fix. XLab's "resilience" line is about iteration speed under that reality.
Operators advertise ~4 Tbps on a clearnet site dressed as a stress tester. Marketing claim, not a measured peak from a major mitigator for this family. Same reporting cites the public record at 31.4 Tbps from Aisuru/Kimwolf in December 2025, a ceiling Cloudflare's 2026 Threat Report also treats as late-2025's high-water mark. Four is smaller than thirty-one and still enough to ruin an unprotected origin's week.
Two weeks earlier, backbone operator Arelion's July 15 DDoS landscape note said Aisuru alone drove about a third of attack traffic on AS1299, with a 6.1 Tbps observed peak on that backbone and average attack bandwidth up 22% to 6,120 Gbps. Different measurement surface than XLab's bot counts. Useful because it shows how concentrated hyper-volumetric traffic has become around a handful of IoT families. Dysphoria is not Aisuru. It's the next family learning the same cheap-device economics, with C2 built to outlast the cleanup cycles Aisuru already forced. DDoS coverage loves round numbers that migrate between incidents. July 27's documented contribution is population, blockchain tradecraft, and the relay variant, not a new terabit crown. If a major provider later publishes a measured Dysphoria event, that will be a different article, and I'll be glad to update the ranking then, not before.
In just a few months, the family has undergone frequent variant updates and technical iterations, demonstrating extremely strong resilience.
ENS buys time. The relay build is the enterprise itch
Traditional C2 dies when a registrar, host, or sinkhole seizes the domain. Ethereum and Solana name records don't behave like that. Change what an ENS/SNS name resolves to and the fleet follows. DNS-zone monitors miss the channel until someone's already decoding fake IPv6. Unstoppable? No. Costlier to kill cleanly, longer window for a 200k rental inventory to earn. Law enforcement and researchers have pulled blockchain-adjacent C2 before. It just takes different muscle than an ICANN complaint.
I'd worry more about the relay-only build than the stress-tester splash page. A router forwarding 155 ports is a hairpin for other crimeware, credential stuffing, or a quieter C2 that never shows up in volumetric graphs. Two products sharing a codebase until proven otherwise. Enterprise defenders who only watch for flood signatures will feel very smart right up until a credential-stuffing campaign exits through a living-room proxy they never inventoried.
BleepingComputer's unglamorous list still applies, firmware, default passwords, remote admin off when you don't need it. For network operators the uglier work is CPE inventory against that CVE list plus treating UPnP as first-class while relay variants run. Short bursts and proxy abuse can sit underneath or beside credential attacks. A quiet relay farm is a persistence and anonymity problem as much as a bandwidth problem.
XLab and CNCERT have tracked the family since Q1 2026 as something that updates faster than most cleanup campaigns. Blockchain name services won't make routers immortal, but they buy operators time, and 200,000 devices is already a serious rental inventory. Whether ISPs start treating ENS/SNS-resolved IoT C2 as a standard detection category, or each new family gets a fresh public lesson, is still open. I'd rather see the boring detection work than another round of terabit theater with the wrong botnet's number attached.
Keep the numbers in their lanes
200k devices is XLab's population estimate. 740k is a peak daily ping count. 4 Tbps is an operator advertisement. 31.4 Tbps is someone else's measured record. 6.1 Tbps is Arelion's Aisuru observation on one backbone. Mixing those into one breathless paragraph is how DDoS stories go wrong. Dysphoria earns attention for ENS/SNS C2 and the relay fork. It has not, in the July 27 reporting, earned a new crown. I'll update that sentence if a mitigator publishes otherwise.
For home networks the advice stays boring on purpose: change defaults, kill remote admin you don't need, patch when vendors actually ship fixes. For ISPs and enterprises, the relay variant is the reason to care beyond another stresser brand name. A living-room router with 155 UPnP forwards is infrastructure for someone else's crime, not just a DDoS node with a cute blockchain trick.
XLab's resilience quote is about iteration speed. That speed is the actual story. ENS and SNS are how the operators buy days. Days are enough when your inventory is 200,000 devices that still answer on Telnet with a password someone set in 2019 and never touched again. Patch the CPE you can reach. Inventory the rest. Leave the terabit crown arguments to whoever publishes a measured event with clear methodology attached to it next.
- Zero Trust
- Edge Computing




