A botnet is a network of computers, servers, routers or IoT devices infected with malware and remotely controlled by an attacker as a single army of “bots”.
How a botnet works
Devices are infected through malware, weak or default passwords and unpatched vulnerabilities. Each infected device – a bot or zombie – contacts the botmaster’s command and control infrastructure and waits for orders. Older botnets used a central server; modern ones use peer-to-peer networks, domain generation algorithms or legitimate services to be harder to take down.
Botnets are rented out for:
- DDoS attacks;
- spam and phishing campaigns;
- credential stuffing and click fraud;
- residential proxy services that hide criminal traffic;
- distribution of other malware, including ransomware, and crypto mining.
Why botnets matter for security
Botnets give criminals massive scale at almost no cost. In 2016 Mirai, built from cameras and routers with factory passwords, took down the DNS provider Dyn and with it major websites. Emotet and Qakbot delivered ransomware to thousands of companies until police operations took them down in 2021 and 2023. In 2024 the US Department of Justice dismantled the 911 S5 proxy botnet of about 19 million IP addresses, and Operation Endgame disrupted several malware loaders. The owners of infected devices usually never notice anything except slower performance.
How to protect your devices
- Change default passwords on routers, cameras and NAS devices and install firmware updates.
- Do not expose Telnet, SSH or admin panels to the internet unnecessarily.
- Replace IoT devices that no longer receive security updates.
- Keep endpoint protection active and watch for unusual outbound traffic.