CRITICAL: Dysphoria Botnet Special Report

LAST UPDATED: 2026-08-13

DEFAULT SEVERITY LEVEL: CRITICAL

This Special Report contains information about ~ 296,000 devices compromised by the Dysphoria botnet. Dysphoria targets IoT devices and its primary function appears to be for use in DDoS-attacks. Recently the botnet has gotten residential proxy functionality.

Shadowserver Special Reports are unlike all of our other standard free daily network reports. They do not cover a specific daily 24-hour time period. Instead, we send out Special Reports in situations where we are able to share one-time, high value datasets that we feel should be reported responsibly for maximum public benefit. Sometimes there are incidents when it would be useful to be able to notify potential victims about events or breaches that may have impacted them outside of the previous 24-hour period, when it may take a number of days for incident responders to conduct forensic investigations and analyzed data becomes available for sharing with potential victims. Although the events included in these Special Reports will fall outside of our usual 24-hour daily reporting window, we believe that there would still be significant benefit to our constituents in receiving and, hopefully, acting on the retrospective data.

If you have missed a Special Report because you were NOT yet a subscriber at the time a report was pushed out, simply subscribe for your network now and specifically request all recent Shadowserver Special Reports – and we will regenerate them specifically for your network, at no cost.

Note that the data shared across Special Reports may differ on a case by case basis, hence the report formats for individual Special Reports may be different.

Note that exact timestamps were not available for individual events, so the timestamp field is set to “2026-08-12 00:00:00”. However, you can use the last_seen field for the exact timestamp of the last event seen.

This Special Report has severity level CRITICAL set on all events. Severity levels are described here.

Filename prefix: 2026-08-12-special. Note: these are accessible in the API using 2026-08-12 as the search date.

Fields

  • timestamp
    The timestamp has been set to "2026-08-12 00:00:00", to represent when this one-off data set was distributed.
  • ip
    IP address of the affected device
  • port
    TCP or UDP port identified
  • protocol
    Protocol associated with the malicious activity
  • asn
    Autonomous System Number of the affected device
  • geo
    Country of the affected device
  • region
    Region of the affected device
  • city
    City of the affected device
  • hostname
    Hostname of the affected device (may be from reverse DNS)
  • naics
    North American Industry Classification System Code
  • sector
    Sector of the IP in question
  • tag
    Additional tags for more insight
  • infection
    Name of botnet, for example dysphoria
  • public_source
    Source of data (if made available)
  • status
    Status of the affected IP
  • detail
    URL to obtain more detail
  • account
    Account compromised (unused)
  • method
    Request method (unused)
  • device_vendor
    Vendor of the infected device
  • device_model
    Model of the infected device
  • device_version
    Version of the infected device
  • severity
    Severity level
  • hostname_source
    Hostname source
  • first_seen_time
    When activity was first observed
  • last_seen_time
    When activity was last observed
  • potential_exposure_time
    Potential exposure time - difference between first_seen_time and last_seen_time
  • user_agent
    User agent making the observed query

Sample

"timestamp","ip","port","protocol","asn","geo","region","city","hostname","naics","sector","tag","infection","public_source","status","detail","account","method","device_vendor","device_type","device_model","device_version","severity","hostname_source","first_seen_time","last_seen_time","potential_exposure_time","user_agent"
"2010-02-10 00:00:00",192.168.0.1,,tcp,64512,ZZ,Region,City,node01.example.com,0,,,dysphoria,,,,,,,,,,critical,ptr,,"2026-08-07 13:51:39",,
"2010-02-10 00:00:01",192.168.0.2,,tcp,64512,ZZ,Region,City,node02.example.com,0,,,dysphoria,,,,,,,,,,critical,ptr,,"2026-08-07 13:51:29",,
"2010-02-10 00:00:02",192.168.0.3,,tcp,64512,ZZ,Region,City,node03.example.com,0,,,dysphoria,,,,,,,,,,critical,ptr,,"2026-08-07 13:51:29",,

Our 145 Report Types