A botnet is a network of compromised devices controlled by one attacker. Each infected machine is called a bot or zombie. The owner usually has no idea. The devices range from home routers and IP cameras to full servers and industrial controllers. The attacker commands them through a command-and-control channel, often using IRC, HTTP, or peer-to-peer protocols. The botnet can then be rented out for distributed denial-of-service attacks, spam campaigns, credential stuffing, or cryptocurrency mining.
Mirai made headlines in 2016 by infecting hundreds of thousands of IoT devices with default passwords and launching record-breaking DDoS attacks. The source code leaked, and variants spread for years. Emotet built a botnet of millions of machines and sold access to ransomware crews. The economics are simple. Compromised devices are cheap, plentiful, and hard to trace. Takedowns happen. Law enforcement seizes command servers and arrests operators. The botnet regrows, often within weeks. Defense is mostly hygiene. Change default passwords. Patch firmware. Segment IoT devices on a separate network. Monitor for unusual outbound traffic. The devices you forget about are the ones attackers find.
Botnet uses
- DDoS — flood a target with traffic
- Spam — send bulk email from many IPs
- Credential stuffing — test stolen logins at scale
- Crypto mining — use victim CPU power for profit
A botnet is a rented army. The attacker does not need to own the soldiers.
Comments
No comments yet. Be the first to share a thought.
Leave a comment