Botnet
A botnet is a network of malware-infected devices an attacker controls remotely, rented out to send spam, spread phishing, and disguise credential attacks.
A botnet is a network of compromised devices — PCs, servers, routers, cameras, phones — that all obey a single attacker, called the botmaster or herder. Each infected machine ("bot" or "zombie") keeps working normally for its owner while quietly executing commands in the background. Individually a bot is worthless; a hundred thousand of them are industrial infrastructure, and that infrastructure is rented by the hour on criminal markets to whoever needs scale or anonymity.
How it works
Devices join a botnet the way they catch any malware: phishing attachments, malicious downloads, malvertising, or — for routers and IoT gear — unpatched vulnerabilities and default passwords. The bot then connects to command-and-control infrastructure and waits. What the herder does with the swarm varies by customer: sending spam and phishing at volumes no single server could achieve, flooding targets offline in DDoS attacks, email bombing a victim's inbox to bury security alerts, hosting or proxying malicious content, and mining cryptocurrency. For security teams, the most relevant use is disguise: credential stuffing and password spraying campaigns are routed through botnets and residential proxies so that millions of login attempts arrive from millions of ordinary home IP addresses, defeating simple rate limiting and IP blocking. The same laundering makes phishing infrastructure harder to trace and block.
How to defend against it
There are two problems: keeping your devices out of botnets, and defending against botnets used by others. For the first, patching, replacing default credentials on network equipment, endpoint protection, and user education about malicious downloads do most of the work — every infection is a recruit, and many begin with one employee running the wrong installer, the supply chain we trace in our infostealer guide. For the second, assume attack traffic will look residential: defend logins with multi-factor authentication and risk-based detection rather than IP reputation alone, and treat sudden floods of email or traffic as potential cover for something quieter happening at the same time.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo