🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
A botnet is a network of internet-connected devices infected with malware and controlled remotely by an attacker as a single system, known as a bot herder or botmaster.
Each infected device, called a bot or zombie, keeps working normally for its owner while it takes instructions from command-and-control (C2) infrastructure.
Routers, IP cameras, Android TV boxes, servers, and corporate workstations all end up in botnets, and the operators rent that capacity out. CloudSEK's threat research team tracked one loader-as-a-service botnet whose attack volume rose more than 230% between July and August 2025 while it pushed RondoDoX, Mirai, and Morte payloads onto routers, IoT devices, and enterprise applications.
Botnet operators run a rental business, and understanding the revenue streams explains which devices they hunt for and how long they stay quiet.
Proxy rental changed the economics more than any other line on that list. An operator running a quiet proxy network earns steadily without the takedown pressure that record-breaking DDoS attacks bring, so infected devices stay in place for months.
A botnet works by infecting devices, registering them with control infrastructure, and issuing commands that thousands of devices execute at once.

CloudSEK's analysis of exposed C2 logs showed this sequence in operational detail: automated login attempts against admin panels, shell commands injected into router configuration fields, device fingerprinting, and then architecture-specific binaries pushed to whichever hosts responded.
Botnet architecture determines how resilient the network is when defenders find and seize its infrastructure.
Bots in a centralized botnet poll one server or a small cluster of servers over HTTP, HTTPS, or a chat protocol. Operators gain simple control and fast tasking.
Defenders gain one point to sinkhole, so seizing a handful of servers ends many of these operations.
Peer-to-peer designs remove the central server from the equation entirely. Every bot holds a list of peers and relays commands onward, so taking down individual nodes leaves the network intact and forces defenders into slower poisoning and enumeration work.
Many botnet families avoid hardcoded server addresses in the implant altogether. A domain generation algorithm produces hundreds of candidate domains a day, and the operator registers only the ones needed.
Fast-flux hosting adds a second layer by rotating the IP addresses behind a domain every few minutes.
Modern implants carry backup channels for the moment a primary server disappears. Operators hide tasking in cloud storage buckets, pastebin-style sites, Telegram channels, blockchain transactions, and Tor hidden services, all of which blend with traffic that enterprises allow by default.
Botnets are grouped by the devices they recruit, and each group creates a different defensive problem.

Device class predicts detection difficulty as much as it predicts attacker intent. A compromised laptop shows up in endpoint telemetry, and a compromised camera generates no logs at all until its traffic crosses a firewall.
Volumetric floods saturate bandwidth, protocol attacks exhaust firewall and load balancer state tables, and application-layer floods drain server resources with requests that look legitimate.
Extortion follows in many campaigns: a short demonstration attack, then a ransom demand to prevent a longer one.
Botnets replay stolen username and password pairs across login endpoints, spreading attempts over thousands of addresses so that per-IP rate limits never trigger. Pairing leaked credential monitoring with multi-factor authentication removes most of the value from these campaigns.
Loader botnets sell footholds, and ransomware crews buy them. An infection that looks like commodity malware on one workstation becomes the first stage of a domain-wide encryption event days later, a chain documented across ransomware intelligence reporting.
Infostealer bots harvest browser credentials, cookies, and documents, then upload them to operator infrastructure and on to criminal markets.
State-linked groups build separate botnets from routers and edge devices to relay their own traffic, hiding advanced persistent threat operations behind residential addresses in the target country.
Enterprise consequences run in both directions, and the outbound half gets overlooked. Devices inside a network that join a botnet consume bandwidth, land corporate IP ranges on blocklists, and generate abuse complaints.
Broadband operators have reported outbound floods from infected customer devices heavy enough to degrade service for neighboring subscribers.
Explore notable botnets active in 2026 and the attack techniques they use to target systems, networks, and connected devices.
Cloudflare attributed a 31.4 Tbps attack to the Aisuru and Kimwolf botnet in its Q4 2025 DDoS report, the largest publicly disclosed attack on record, sustained for 35 seconds.
That same report counted 47.1 million DDoS attacks mitigated across 2025, up 121% year over year, with more than 71% of HTTP floods traced to known botnets.
Estimates of the network's size range from one to four million devices, largely low-cost Android TV boxes and home routers. KrebsOnSecurity reported in October 2025 that the operators had retooled the malware to rent infected devices as residential proxies, a quieter business than record-setting floods.
RondoDox takes the opposite approach to stealth from most modern families. Trend Micro documented an exploit shotgun strategy that fires more than 50 exploits across 30-plus vendors at internet-facing routers, DVRs, NVRs, CCTV systems, and web servers.
The operators accept noisy failures because volume produces infections faster than precision does.
CloudSEK found RondoDoX distributed alongside Mirai and Morte through the same loader infrastructure, which shows how botnet families share delivery channels instead of competing for devices.
Mirai set the template in 2016 by scanning for default credentials on IoT devices, and its published source code produced a decade of variants.
Current campaigns still run Mirai payloads alongside newer families, a lineage covered in CloudSEK's guide to the Mirai botnet.
Law enforcement targeted the Elysium botnet alongside the Rhadamanthys infostealer and VenomRAT in November 2025.
Europol reported that the operation took down more than 1,025 servers and seized 20 domains, with the infrastructure tied to hundreds of thousands of infected computers and several million stolen credentials.
To detect botnet activity, security teams watch outbound traffic and name resolution, because infected devices reveal themselves when they call home rather than when they are infected.
Bots relying on domain generation algorithms produce heavy NXDOMAIN volume as they cycle through unregistered names.
Queries for newly registered domains, high-entropy hostnames, and dynamic DNS providers deserve the same scrutiny, and DNS logging feeds these detections into broader security monitoring.
On managed endpoints, look for unsigned processes with network listeners, scheduled tasks pointing at temporary directories, and JSON-RPC calls to mining pools.
Embedded devices give only indirect evidence: degraded performance, reboots into unknown configurations, altered DNS settings, and firmware checksums that no longer match the vendor image.
Intelligence from outside the network closes the loop. Abuse notifications, blocklist entries naming corporate IP ranges, and dark web chatter about the organization's devices all indicate infections that internal tooling has missed.
Preventing botnet infections means closing the two doors operators use most: internet-exposed devices with weak credentials and users who run attachments.
Coordinated takedowns disrupt botnets without eliminating them, for reasons built into how these networks are designed.
Takedowns still matter, because they impose cost on operators and buy defenders time. The practical lesson for a SOC is that removal of upstream infrastructure never substitutes for finding and cleaning infected devices on its own network.
While hunting malicious infrastructure, CloudSEK's TRIAD team found an exposed logger server holding six months of botnet command-and-control activity. The logs named the device types under attack and the injection points being abused.
They exposed the old CVEs in play across WebLogic, WordPress, and vBulletin, plus the drop hosts staging payloads.
Customers whose technology stack matched those vectors were alerted while the campaign was still running. CloudSEK Threat Intelligence produced that warning by tracking the campaign, the malware families behind it, and the exposures that decided which customers were in scope.
Cleaning infected devices stays an internal job. Knowing which malware families are hunting the organization's device types decides where that work starts.
A bot herder, or botmaster, is the operator who controls a botnet, issues commands to infected devices, and rents or sells that capacity to other criminals.
A worm spreads itself automatically between systems. A botnet is the controlled network that results once infected devices connect to an operator's command infrastructure.
Yes. Building, operating, renting, or using a botnet constitutes unauthorized access and computer misuse under criminal law in most countries.
Yes. Low-cost Android TV boxes and phones running outdated firmware form a large share of current botnets, including the devices behind record DDoS attacks.
Yes, for most consumer devices, though firmware-resident implants survive a reset. Devices with no vendor patch available need replacement.
Partially. Inbound firewall rules block scanning, and egress filtering blocks C2 traffic, yet neither stops malware delivered through email or software downloads.
