A newly tracked botnet known as Dysphoria has infected roughly 200,000 internet-connected devices worldwide and is actively leveraging them for distributed denial-of-service (DDoS) campaigns and malicious traffic relay, according to reporting by BleepingComputer.

Security researchers say the operation has scaled rapidly by exploiting a pair of well-documented, high-impact vulnerabilities rather than relying on zero-day exploits. The primary infection vectors identified are CVE-2023-1389, a command-injection flaw affecting certain TP-Link routers, and CVE-2023-46609, a remote code execution vulnerability in Apache Hadoop. Both weaknesses have been public for some time, yet large numbers of unpatched systems remain exposed on the public internet, giving operators a ready pool of targets.

Once compromised, devices are folded into the Dysphoria network and can be directed to flood targets with traffic or to proxy other malicious activity. Access to portions of the botnet is reportedly offered for rent on underground forums, turning the infrastructure into a botnet-as-a-service platform. This model lowers the barrier for a wider set of threat actors who wish to launch DDoS attacks or obscure the origin of their own traffic without building and maintaining their own botnet.

Command-and-control communications are routed through the Tor network, and the malware incorporates anti-analysis techniques designed to frustrate reverse engineering and automated sandbox detection. These design choices complicate both real-time detection by network defenders and longer-term disruption efforts by law enforcement.

The growth of Dysphoria underscores a persistent pattern in the threat landscape: many large-scale botnets continue to expand by systematically abusing known flaws in widely deployed consumer and enterprise equipment. Routers and big-data platforms that sit at the edge of networks or process large volumes of data are especially attractive because they often remain online continuously and may receive less frequent security attention than endpoint systems.

For IT and open-source communities, the incident serves as a concrete reminder that delayed patching of internet-facing infrastructure carries direct operational risk. Unmitigated devices can be silently recruited into criminal infrastructure, potentially exposing organizations to secondary legal or reputational consequences if their systems are later linked to attacks against third parties.

Defenders are advised to treat remediation of CVE-2023-1389 and CVE-2023-46609 as an immediate priority on any publicly reachable systems. Complementary measures include monitoring for unusual outbound connections, especially those destined for Tor exit nodes or previously identified malicious infrastructure, and reviewing network logs for signs of anomalous traffic volumes that could indicate participation in DDoS activity.

While the full range of propagation techniques used by Dysphoria beyond the two named CVEs is still under investigation, the core lesson remains clear: the combination of unpatched legacy vulnerabilities, rental marketplaces for botnet capacity, and anonymity-enhancing technologies continues to enable rapid, large-scale compromise. Sustained attention to basic hygiene—timely patching, reduced internet exposure of management interfaces, and continuous monitoring—remains one of the most effective countermeasures available to organizations of every size.


根據BleepingComputer的報導,一個新被追蹤、名為Dysphoria的殭屍網絡已感染全球約20萬台互聯網連接裝置,並正積極利用這些裝置進行分散式阻斷服務攻擊及惡意流量中繼。

安全研究人員表示,該行動並非依賴零日漏洞,而是透過利用一對文獻記載充分、影響力高的漏洞而迅速擴散。已識別的主要感染途徑是CVE-2023-1389(影響部分TP-Link路由器的命令注入漏洞)及CVE-2023-46609(Apache Hadoop的遠端執行漏洞)。兩項弱點已被公開一段時間,但仍有大量未修補系統暴露在公共互聯網上,為操作者提供了現成的攻擊目標池。

裝置一旦被攻陷,便會被納入Dysphoria網絡,並可被指令向目標發送大量流量或代理其他惡意活動。據報,該殭屍網絡部分存取權限已在地下論壇提供租賃,將基礎設施轉化為「殭屍網絡即服務」平台。此模式降低了更多威脅行為者發動DDoS攻擊或隱匿自身流量來源的門檻,無須自行建立及維護殭屍網絡。

指令與控制通訊透過Tor網絡路由,而惡意軟件整合了旨在阻礙逆向工程及自動化沙箱檢測的反分析技術。這些設計選擇增加了網絡防禦者的即時檢測難度,亦令執法部門的長期瓦解工作變得複雜。

Dysphoria的增長凸顯了威脅環境中一個持續存在的模式:許多大規模殭屍網絡繼續透過系統性濫用廣泛部署的消費及企業設備中的已知漏洞而擴張。位於網絡邊緣或處理大量數據的路由器及大數據平台尤其具吸引力,因其往往持續在線,且獲得的安全關注可能少於端點系統。

對IT及開源社群而言,此事件是一個具體提醒:延遲修補面向互聯網的基礎設施,會帶來直接的營運風險。未經緩解的裝置可能被悄悄招募至犯罪基礎設施中,若其系統稍後被發現與針對第三方的攻擊有關,或會令組織面臨間接的法律或聲譽後果。

建議防禦者將修補CVE-2023-1389及CVE-2023-46609列為任何公開可達系統的即時優先事項。補充措施包括監測異常出站連接(尤其針對Tor出口節點或先前已識別的惡意基礎設施),並審查網絡日誌以尋找可能指示參與DDoS活動的異常流量跡象。

雖然Dysphoria在兩個已知CVE之外的完整傳播技術仍在調查中,但核心教訓依然明確:未修補的舊有漏洞、殭屍網絡容量租賃市場以及匿名增強技術的結合,持續促成快速且大規模的入侵。持續關注基本衛生措施——及時修補、減少管理界面的互聯網暴露,以及持續監測——仍然是各類規模組織可用的最有效反制措施之一。

新聞來源 / Original News Source