Computer Security

What Is a Botnet?

A botnet is a network of internet-connected devices infected with malware and controlled remotely by an attacker through a command-and-control server. The infected devices, called bots or zombies, link computers, servers, routers, and Internet of Things (IoT) gear into one coordinated group the operator directs without the owners’ knowledge. The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI rank botnets among the largest sources of distributed denial-of-service attacks and spam.

In shortA botnet is a network of malware-infected devices (bots or zombies) controlled remotely by an attacker through a command-and-control (C2) server. Centralized C2 routes every bot to one server; peer-to-peer C2 relays commands between bots with no single point to seize. Botnets power DDoS, spam, credential stuffing, cryptomining, and click fraud.
5.6 Tbps
Record Mirai-variant DDoS (2024)
13,000+
IoT devices in that attack
1-4M
Aisuru botnet infected hosts (2025)
8.3M
DDoS attacks blocked, Q3 2025

What Is a Botnet?

A botnet is a network of compromised devices controlled remotely by an attacker through a command-and-control server. It combines many infected devices, called bots or zombies, into a single tool the operator commands. The defining traits are listed below:

  • Compromised devices: each is infected with malware that places it under an attacker’s control.
  • Remote control: one operator (the botmaster or bot herder) directs every device from a central command point.
  • Command-and-control server: pushes instructions to all infected devices in the network at once.
  • Coordinated scale: combining the devices produces attacks no single device could.

A botnet is built from devices infected by malicious software such as worms and trojans, making it one of the types of malware threats. The remote control that defines a botnet is the trait the following sections examine in detail.

How Is a Botnet Built and Commanded?

A botnet is built and commanded in a repeatable cycle: infect a device, phone home to the C2 server, wait for orders, then act as a fleet. The stages are listed below:

  • Infect. Malware compromises a device through a worm, trojan, phishing message, or exploited vulnerability (default-password IoT gear is the easiest target).
  • Enroll. The new bot silently connects to the command-and-control server and registers itself in the network.
  • Wait. The bot stays dormant, checking in for instructions so the owner notices nothing unusual.
  • Command. The botmaster pushes one order to the C2 channel and every bot receives it at the same time.
  • Act. The fleet executes together, supplying the scale behind a DDoS flood, spam run, or credential-stuffing wave.

Each stage maps to a defense: patching and strong passwords stop the infect stage, and monitoring outbound traffic catches the enroll and wait stages before the fleet acts.

How Are Devices Recruited Into a Botnet?

Devices are recruited when malware infects them through worms, trojans, phishing, or exploited vulnerabilities, then connects each device to a command-and-control server. Recruitment uses the same infection paths as other malware. The methods are listed below:

  • Worm propagation spreads botnet malware automatically across networks to new devices.
  • Trojan delivery hides botnet malware inside a program that appears legitimate.
  • Phishing tricks a user into running the malware that enrolls the device.
  • Exploited vulnerabilities let malware infect unpatched devices, including default-password IoT devices.

A device joins a botnet silently after infection, often by a computer worm that spreads the recruiting malware automatically. Devices with default passwords or unpatched firmware are recruited at scale, according to CISA advisories on botnet activity.

What Are the Command-and-Control Models of a Botnet?

The command-and-control models are centralized, where bots connect to one server, and peer-to-peer, where bots relay commands among themselves. The model defines how an operator directs the botnet, and how defenders disrupt it. The models are listed below:

What Are the Command-and-Control Models of a Botnet? - What Is a Botnet?
  • Centralized control connects every bot to a single command-and-control server that issues instructions.
  • Peer-to-peer (P2P) control relays commands between bots, with no single server to disable.
  • Centralized models are easier to operate but fail if the central server is seized.
  • Hybrid models start on a central C2 and fall back to peer-to-peer if that server is taken down.
Why P2P is harder to killA centralized botnet collapses when its command server is seized, so operators adopt peer-to-peer or hybrid control to resist takedown. With no single node to disable, defenders must reach many peers at once, which is why P2P botnets survive longer, according to FBI botnet disruption reports.

What Are Botnets Used For?

Botnets are used for DDoS attacks, sending spam, credential stuffing, cryptomining, click fraud, and spreading further malware. A botnet applies its combined devices to tasks that require scale. The main uses are below:

Related Articles

DDoS attacks

Flood a target with junk traffic from thousands of bots at once. This is the flagship use; a Mirai-variant botnet drove a record 5.6 Tbps flood from 13,000+ IoT devices in 2024.

Spam & phishing

Send high-volume fraud and malware email from infected hosts, hiding the real sender behind many compromised devices.

Credential stuffing

Replay stolen username and password pairs against banking, email, and retail sites at massive scale to hijack accounts.

Cryptomining

Hijack the combined CPU and GPU of the bots (cryptojacking) to mine cryptocurrency for the operator at the victims’ expense.

Click fraud

Generate fake ad clicks and bot traffic to drain advertiser budgets and inflate the operator’s ad revenue.

Proxy abuse

Rent compromised IP addresses as anonymizing residential proxies for fraud and abuse, as the 911 S5 botnet did.

A botnet supplies the distributed traffic behind a DDoS attack, one of the common network attacks botnets enable. Credential stuffing tests stolen passwords at scale, which makes unique passwords and two-factor authentication effective defenses for individual accounts.

What Are Examples of Botnets?

Examples of botnets include the Mirai botnet, which infected IoT devices, and the Emotet botnet, which spread through email. Each example shows how compromised devices have been coordinated in real incidents. The examples are listed below:

  • Mirai infected IoT devices with default passwords and launched record DDoS attacks in 2016; its 2016 source-code release spawned 100+ variants still active in 2026.
  • Emotet spread through malicious email attachments and delivered other malware to victims before a 2021 takedown.
  • Conficker grew from a worm that infected millions of Windows devices from 2008.
  • Aisuru is a Mirai-class IoT family of 1-4 million infected Android TVs and home routers that eclipsed Mirai as the apex botnet of 2025.

The Mirai botnet, documented by CISA, used IoT devices with default credentials to launch one of the largest recorded DDoS attacks. The Emotet botnet spread through email and delivered ransomware and other payloads before an international operation disrupted it in 2021.

What Is an IoT Botnet?

An IoT botnet is a botnet built from infected Internet of Things devices, such as cameras, routers, and smart home gear, often compromised through default passwords. It exploits the weak security common in connected devices. The traits are listed below:

  • Connected devices include cameras, routers, and smart home products with always-on internet access.
  • Default passwords on many IoT devices let malware infect them without cracking credentials.
  • Infrequent updates leave IoT firmware vulnerable for long periods after release.
  • Large scale arises because billions of IoT devices are connected worldwide and rarely monitored.
IoT botnets are the modern apexMirai proved the model in 2016, and 2025 took it further: the Aisuru family reached an estimated 1-4 million bots and peaks near 29.7 Tbps, and Cloudflare blocked 8.3 million DDoS attacks in Q3 2025 alone (up 40% year over year). Changing default passwords and updating firmware remain the primary IoT defenses, since weak credentials are the common entry point.

How Do You Defend Against a Botnet?

Defense against a botnet combines software updates, strong unique passwords, antivirus software, network monitoring, and changing default credentials on every device. It both prevents recruitment and detects an infected device. The defenses are listed below:

  • Software and firmware updates close the vulnerabilities botnet malware exploits to infect devices.
  • Strong unique passwords replace the default credentials that IoT botnets exploit.
  • Antivirus software detects and removes the malware that enrolls a device in a botnet.
  • Network monitoring flags the unusual traffic an infected device sends to a command server.

Changing default passwords and updating firmware prevent most IoT botnet recruitment, according to CISA guidance. Detecting an infected device relies on antivirus software and on monitoring for the outbound connections a bot makes to its command-and-control server, supported by the steps to remove malware from a PC.

How Do You Know If a Device Is Part of a Botnet?

A device in a botnet shows signs such as slow performance, unexpected network activity, high data usage, crashes, and unexplained outbound connections. The symptoms appear in performance and network behavior. The signs are listed below:

How Do You Know If a Device Is Part of a Botnet? - What Is a Botnet?
  • Slow performance results from the device running botnet tasks in the background.
  • Unexpected network activity appears as the device contacts a command-and-control server.
  • High data usage rises as the device sends spam or attack traffic without the owner’s action.
  • Frequent crashes occur as botnet malware consumes processing and memory.

Unexplained outbound connections to unfamiliar addresses are a common sign of a botnet infection, according to CISA. Detecting these signs relies on antivirus software and network monitoring that flags the traffic an infected device sends to its command server.

How Are Botnets Taken Down?

Botnets are taken down by seizing command-and-control servers, sinkholing the domains bots contact, and coordinating between law enforcement and security companies. A takedown disrupts the control an operator holds over the infected devices. The methods are listed below:

  • Server seizure shuts down the command-and-control servers a centralized botnet depends on.
  • Sinkholing redirects the domains bots contact to servers controlled by defenders.
  • Law enforcement action arrests operators and dismantles the infrastructure behind a botnet.
  • Coordinated disruption joins security companies and agencies to disable a botnet at scale.

The Emotet botnet was disrupted in 2021 through a coordinated international law enforcement operation that seized its infrastructure, according to Europol, and the 911 S5 proxy botnet was dismantled in 2024. A peer-to-peer botnet resists server seizure, which makes such botnets harder to dismantle than a centralized one.

What Is the Difference Between a Botnet and a Worm?

A botnet is a network of devices controlled by an attacker, while a worm is self-replicating malware that spreads on its own, and a worm is often the tool that recruits devices into a botnet. The botnet is the controlled network; the worm is one method of building it. The differences are listed below:

  • A botnet is the network of compromised devices under remote control.
  • A worm is malware that self-replicates to spread across devices.
  • A worm can deliver the malware that enrolls a device into a botnet.
  • A botnet uses its devices for coordinated attacks once recruitment is complete.

A worm and a botnet work together when a computer worm spreads the malware that connects each infected device to a command server. The worm performs the recruitment, while the botnet performs the coordinated attacks afterward.

Last Thoughts on Botnets

A botnet is a network of compromised devices (bots or zombies) controlled remotely through a command-and-control server, combining many infected devices into one coordinated tool. Devices are recruited through worms, trojans, phishing, and exploited vulnerabilities, and the operator directs them through centralized, peer-to-peer, or hybrid control. The 2024 record 5.6 Tbps DDoS and the 2025 Aisuru family show the scale IoT botnets now reach, while the Mirai and Emotet cases show how they are built and dismantled.

Defense combines software updates, strong unique passwords, antivirus software, and network monitoring. Readers can continue with the guide to common network attacks, the overview of malware, the explanation of a computer worm, or the introduction to cybersecurity.

Key Takeaways:

  • A botnet is a network of malware-infected devices (bots or zombies) controlled remotely by an attacker.
  • It is built in a cycle: infect a device, phone home to C2, wait for orders, then act as a fleet.
  • Command-and-control models are centralized (one server), peer-to-peer, and hybrid.
  • Botnets are used for DDoS, spam, credential stuffing, cryptomining, and click fraud.
  • Examples span the 2016 Mirai IoT botnet, the email-spread Emotet, and the 2025 Aisuru family (1-4M bots).
  • Defense combines updates, strong passwords, antivirus software, and network monitoring.

Frequently Asked Questions (FAQs)

What is a botnet in simple terms?

A botnet is a network of internet-connected devices infected with malware and controlled remotely by an attacker through a command-and-control server. The devices, called bots, act together on the operator’s commands.

How does a device join a botnet?

A device joins a botnet when malware infects it through a worm, trojan, phishing message, or exploited vulnerability, then connects it to a command-and-control server. IoT devices with default passwords are recruited at scale.

What are botnets used for?

Botnets are used for distributed denial-of-service attacks, sending spam, credential stuffing, cryptomining, and spreading further malware. The combined devices give a botnet the scale these tasks require.

What is the Mirai botnet?

The Mirai botnet infected Internet of Things devices that used default passwords, such as cameras and routers, and launched one of the largest recorded DDoS attacks in 2016.

What is an IoT botnet?

An IoT botnet is a botnet built from infected Internet of Things devices, such as cameras, routers, and smart home products. These devices are often compromised through unchanged default passwords.

How do you protect against a botnet?

Protect against a botnet by updating software and firmware, replacing default passwords with strong unique ones, running antivirus software, and monitoring the network for unusual outbound traffic.

Nizam Ud Deen

Muhammad Nizam Ud Deen Usman is the founder of theCoreiTech and the author of The Local SEO Cosmos. Nizam works as an SEO consultant and content strategy expert with more than a decade of experience in digital marketing and IT, and he also founded ORM Digital Solutions, a digital agency serving medium and large businesses. He holds a degree from the University of Education, Lahore (Multan Campus), and was listed among the top 20 SEO experts in Pakistan in 2024. Nizam started theCoreiTech in 2012 to make computers easier to understand and use for everyone. Connect with Nizam on LinkedIn (seoobserver), X (@SEO_Observer), or at nizamuddeen.com.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button