Gertrude

@baly56.bsky.social

“It's a universal law - intolerance is the first sign of an inadequate education. An ill-educated person behaves with arrogant impatience, whereas truly profound education breeds humility.” Aleksandr Solzhenitsyn

Happy Birthday to the AMAZING Katie Phang!! Every single day, we’re in awe of your brilliance, integrity, and relentless fight for the truth. Here’s to another year of making a difference. We’re so grateful for you.

Bild

Dysphoria Botnet Infects 200,000 IoT Devices and Hides C2 Behind Blockchain Domains

Dysphoria Botnet Infects 200,000 IoT Devices and Hides C2 Behind Blockchain Domains

Dysphoria has emerged as a fast-moving IoT botnet that has infected an estimated 200,000 devices worldwide. The malware targets routers, cameras, gateways, and other embedded Linux systems, turning poorly protected equipment into resources for cybercriminal operations. Its operators use a mix of Telnet and SSH password attacks alongside known software flaws to gain access. This familiar approach is still effective because many connected devices remain exposed online, run old firmware, or use weak credentials. Analysts at Qianxin identified the malware’s rapid evolution and its unusual use of blockchain-based domains to conceal command-and-control infrastructure. Qianxin said in a report shared with Cyber Security News (CSN) that Dysphoria has repeatedly changed its code and network design since early 2026. The botnet is not limited to launching disruptive traffic floods. Newer variants can convert infected machines into relay nodes, allowing operators to route traffic through compromised devices and make the real control infrastructure harder to identify or remove. This combination of large-scale infection, adaptable code, and hidden control channels makes Dysphoria a significant concern for home users and organizations operating internet-connected equipment. Its activity also shows why  protecting connected IoT devices  requires more than simply changing a device’s default password. Dysphoria Botnet Uses Blockchain Domains Dysphoria’s most notable feature is its use of Ethereum Name Service and Solana Name Service domains to locate its control infrastructure. Rather than relying on one fixed server address, the malware looks up records associated with blockchain domains and obtains data that guides it toward active relay and control systems. The technique gives operators an additional layer of resilience. Blocking a conventional domain or IP address can interrupt a botnet’s communications, but blockchain-linked records may allow attackers to update infrastructure without modifying every infected device. This resembles other campaigns where  blockchain C2 infrastructure tactics  complicated efforts to track malicious servers. Researchers observed that the bot queries ENS and SNS records, then extracts concealed network information from the returned data. In one case, the malware uses a blockchain domain to retrieve relay-distribution nodes, which then provide the addresses used for direct command-and-control communication. The latest samples also use modified encryption routines to hide strings and configuration data. These protections make analysis slower and help the malware avoid simple signatures, while the rotating infrastructure reduces the value of blocking individual indicators alone. Relay Nodes Expand Threat A separate Dysphoria variant discovered in late June removes its DDoS function and focuses entirely on creating relay proxies. It can search for network gateways that support UPnP, open ports automatically, and expose the infected system for traffic relaying. Once active, the relay component can connect external traffic to a remote destination while using the victim device as an intermediary. The report said this creates a hybrid structure in which infected hosts support both DDoS operations and a distributed relay network. Dysphoria spreads through weak Telnet and SSH passwords and exploits vulnerabilities affecting IoT equipment, including older flaws that remain widespread. Commercial operation model and plans (Source – Qianxin) Similar exposure patterns were recently seen in a  router loader service campaign , where attackers abused vulnerable management interfaces to deploy malicious payloads. Monitoring between July 14 and July 20 found 4,401 confirmed active bots in China, while the peak number of overseas bots online reached 239,000. Leaked control-panel screenshots reviewed by researchers indicated the operators maintained a botnet of roughly 200,000 devices and claimed potential DDoS capacity of up to 4 Tbps. Device owners should change default credentials, disable Telnet and remote management where they are not essential, and apply vendor firmware updates promptly. Organizations should also separate IoT equipment from critical systems, monitor unusual outbound connections, and review their wider  IoT security management strategy  to limit the impact of an infected device. Indicators of compromise (IoCs):- Type Indicator Description IP address 217.60.195.160 Download/C2 server with identified FTP banner  IP address 76.164.203.171 Download/C2 server with identified FTP banner  IP address 92.42.100.131 Download/C2 server with identified FTP banner  IP address 78.153.155.152 Download/C2 server with identified FTP banner  Domain i.peer4you.net Critical infrastructure domain  Domain o.peer4you.net Critical infrastructure domain  Domain login.trees4sale.net Relay status reporting domain  Domain www.trees4sale.net Critical infrastructure domain  Domain c2.saintpetersburgresident.ru Critical infrastructure domain  Domain peer.saintpetersburgresident.ru Critical infrastructure domain  Domain kieron.androiddebugbridge.su Critical infrastructure domain  Domain dysphoria.androiddebugbridge.su Critical infrastructure domain  Domain telaviv.androiddebugbridge.su Critical infrastructure domain  Domain jerusalem.androiddebugbridge.su Critical infrastructure domain  Domain node.androiddebugbridge.su Critical infrastructure domain  Domain wow.androiddebugbridge.su Critical infrastructure domain  Blockchain domain m3rnbvs5d.eth ENS domain associated with Dysphoria  Blockchain domain burrberry.eth ENS domain used for relay distribution  Blockchain domain ukranianhorseriding.eth ENS domain used for network infrastructure  Blockchain domain 24carnforth2merseyside.sol SNS domain used for network infrastructure  SHA-1 c1bedea261f325441fb9a75c50b11d0c8fb01ac6 Partial core sample hash  SHA-1 a3b9575897c16cbf6afe3af1aa8b55171ea6edf Partial core sample hash  SHA-1 98db6c78533c176f13b61405cdc3f8fad703325f Partial core sample hash  SHA-1 19c1716d770ea69e8e1418d96d52222396ecb436 Partial core sample hash  SHA-1 273651c02b29f1c07e3177e86c967fc45e9f30f Partial core sample hash  SHA-1 0f955ff909972958098f0d4a06bcc4d6b9eea904 Partial core sample hash  SHA-1 4925081bdec05f64eb4f313420c82d8de957e3002 Partial core sample hash  SHA-1 dcea71b9ab9de8efca301de9e2f7bf11c7132364 Partial core sample hash  SHA-1 df510f6f69a5c149c216c7b3accc4f460d8cf363 Partial core sample hash  SHA-1 b0782a9d6eef2ce02f734a6e5e1d8e0f9a2b65be Partial core sample hash  SHA-1 e7e1694162639ed587625432a79cfaa49f560d11 Partial core sample hash  SHA-1 b7faa44ab0772047a8581bbfdd9c561e28fc66de Partial core sample hash  Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure. The post Dysphoria Botnet Infects 200,000 IoT Devices and Hides C2 Behind Blockchain Domains appeared first on Cyber Security News .

cybersecuritynews.com

It’s that time of year again. Teachers, THANK YOU for what you do. If you need help stocking your room this year, please drop a link to your Classroom Wishlists in the comments! I’ll get as much as I can, and there are always some great members of the community who chip in too!

Bild

Watching recorded episodes of“The View” today. Hot Topics was about a man who bought a house at Auction and discovered three deceased bodies inside. Some discussion concerned haunt possibility. Sigh. Lived seven years in a home we built and despite my nonbeliever position of spirits on a home..1

Last September, Collins accepted a $10,000 donation from Epstein associate Casey Wasserman, including $7,000 to her campaign committee and $3,000 to Dirigo PAC sponsored by Collins. Wasserman also hosted a Hollywood fundraiser for Collins, MTN reported. #EpsteinCoverUp #SusieTheEnabler

More Donations from Epstein Contacts to Susan Collins Uncovered

Collins took money from men on the Epstein list before voting against releasing the files

yahoo.com