What Is a Botnet? How Botnets Work, Types & Defenses

A botnet is a network of infected devices controlled remotely by an attacker. Learn how botnets work, what they are used for, and how to detect and stop them.
Published on
Saturday, September 26, 2026
Updated on
September 26, 2026

A botnet is a network of internet-connected devices infected with malware and controlled remotely by an attacker as a single system, known as a bot herder or botmaster.

Each infected device, called a bot or zombie, keeps working normally for its owner while it takes instructions from command-and-control (C2) infrastructure.

Routers, IP cameras, Android TV boxes, servers, and corporate workstations all end up in botnets, and the operators rent that capacity out. CloudSEK's threat research team tracked one loader-as-a-service botnet whose attack volume rose more than 230% between July and August 2025 while it pushed RondoDoX, Mirai, and Morte payloads onto routers, IoT devices, and enterprise applications.

Botnet Economics: How Operators Profit From Infected Devices

Botnet operators run a rental business, and understanding the revenue streams explains which devices they hunt for and how long they stay quiet.

  • DDoS for hire: Booter and stresser services sell attack capacity by the minute, with prices low enough for schoolyard disputes and high enough for extortion campaigns.
  • Residential proxy rental: Infected home devices are resold as residential proxies, letting buyers route scraping, credential stuffing, and fraud traffic through addresses that look like ordinary broadband users.
  • Loader-as-a-service: Access to compromised machines is sold to other criminals, who push infostealers, remote access trojans, or ransomware onto them.
  • Cryptomining: Idle CPU cycles on routers and servers mine cryptocurrency, monetizing devices with little other criminal value.
  • Credential stuffing and fraud: Distributed login attempts across thousands of IP addresses defeat rate limits that block single-source attacks.
  • Spam and phishing delivery: Mail sent from residential and small-business addresses bypasses reputation filters that block known bulletproof hosts.

Proxy rental changed the economics more than any other line on that list. An operator running a quiet proxy network earns steadily without the takedown pressure that record-breaking DDoS attacks bring, so infected devices stay in place for months.

How a Botnet Works, Stage by Stage

A botnet works by infecting devices, registering them with control infrastructure, and issuing commands that thousands of devices execute at once.

how do botnets Work
  1. Infection: Malware reaches the device through a default password, an unpatched vulnerability in a web interface, a phishing attachment, or a malicious download.
  2. Enrollment: The implant contacts C2 infrastructure, reports device details such as architecture and firmware, and receives a payload built for that platform.
  3. Command and control: Operators push instructions to the whole network or to segments of it, including attack targets, new download locations, and fallback servers.
  4. Execution: Bots carry out the task together, whether that means flooding a target, relaying proxy traffic, mining, or scanning for the next set of victims.
  5. Propagation: Infected devices scan the internet for more vulnerable hosts, which turns every new bot into a recruiter.
  6. Persistence and resale: The implant survives reboots where it can, and access to the device is sold, leased, or reused long after the original campaign ends.

CloudSEK's analysis of exposed C2 logs showed this sequence in operational detail: automated login attempts against admin panels, shell commands injected into router configuration fields, device fingerprinting, and then architecture-specific binaries pushed to whichever hosts responded.

Botnet Command-and-Control Architectures

Botnet architecture determines how resilient the network is when defenders find and seize its infrastructure.

Centralized Botnets

Bots in a centralized botnet poll one server or a small cluster of servers over HTTP, HTTPS, or a chat protocol. Operators gain simple control and fast tasking.

Defenders gain one point to sinkhole, so seizing a handful of servers ends many of these operations.

Peer-to-Peer Botnets

Peer-to-peer designs remove the central server from the equation entirely. Every bot holds a list of peers and relays commands onward, so taking down individual nodes leaves the network intact and forces defenders into slower poisoning and enumeration work.

Domain Generation Algorithms and Fast Flux

Many botnet families avoid hardcoded server addresses in the implant altogether. A domain generation algorithm produces hundreds of candidate domains a day, and the operator registers only the ones needed.

Fast-flux hosting adds a second layer by rotating the IP addresses behind a domain every few minutes.

Fallback and Cover Channels

Modern implants carry backup channels for the moment a primary server disappears. Operators hide tasking in cloud storage buckets, pastebin-style sites, Telegram channels, blockchain transactions, and Tor hidden services, all of which blend with traffic that enterprises allow by default.

Types of Botnets by Device and Target

Botnets are grouped by the devices they recruit, and each group creates a different defensive problem.

types of botnets
  • IoT and router botnets: Cameras, DVRs, and SOHO routers with default credentials or unpatched firmware, valued for bandwidth and for staying online permanently.
  • Windows botnets: Workstations infected by loaders and infostealers, valued for credentials, session tokens, and access that leads to ransomware.
  • Android and smart TV botnets: Low-cost streaming boxes and phones, compromised through preinstalled malware or unofficial app stores.
  • Server and cloud botnets: Exposed management interfaces and vulnerable applications on cloud instances, valued for CPU power and clean IP reputation.
  • Proxy botnets: Any device with a residential or mobile IP address, recruited purely to relay someone else's traffic.
  • Social bot networks: Automated and stolen accounts used for scams, engagement fraud, and coordinated manipulation, which operate without malware on any endpoint.

Device class predicts detection difficulty as much as it predicts attacker intent. A compromised laptop shows up in endpoint telemetry, and a compromised camera generates no logs at all until its traffic crosses a firewall.

What Botnets Are Used For Against Enterprises

Distributed Denial-of-Service Attacks

Volumetric floods saturate bandwidth, protocol attacks exhaust firewall and load balancer state tables, and application-layer floods drain server resources with requests that look legitimate.

Extortion follows in many campaigns: a short demonstration attack, then a ransom demand to prevent a longer one.

Credential Stuffing and Account Takeover

Botnets replay stolen username and password pairs across login endpoints, spreading attempts over thousands of addresses so that per-IP rate limits never trigger. Pairing leaked credential monitoring with multi-factor authentication removes most of the value from these campaigns.

Malware Delivery and Ransomware Staging

Loader botnets sell footholds, and ransomware crews buy them. An infection that looks like commodity malware on one workstation becomes the first stage of a domain-wide encryption event days later, a chain documented across ransomware intelligence reporting.

Data Theft and Espionage

Infostealer bots harvest browser credentials, cookies, and documents, then upload them to operator infrastructure and on to criminal markets.

State-linked groups build separate botnets from routers and edge devices to relay their own traffic, hiding advanced persistent threat operations behind residential addresses in the target country.

Outbound Attacks From Company Devices

Enterprise consequences run in both directions, and the outbound half gets overlooked. Devices inside a network that join a botnet consume bandwidth, land corporate IP ranges on blocklists, and generate abuse complaints.

Broadband operators have reported outbound floods from infected customer devices heavy enough to degrade service for neighboring subscribers.

Botnet Examples Driving Attacks in 2026

Explore notable botnets active in 2026 and the attack techniques they use to target systems, networks, and connected devices.

Aisuru and Kimwolf

Cloudflare attributed a 31.4 Tbps attack to the Aisuru and Kimwolf botnet in its Q4 2025 DDoS report, the largest publicly disclosed attack on record, sustained for 35 seconds.

That same report counted 47.1 million DDoS attacks mitigated across 2025, up 121% year over year, with more than 71% of HTTP floods traced to known botnets.

Estimates of the network's size range from one to four million devices, largely low-cost Android TV boxes and home routers. KrebsOnSecurity reported in October 2025 that the operators had retooled the malware to rent infected devices as residential proxies, a quieter business than record-setting floods.

RondoDox

RondoDox takes the opposite approach to stealth from most modern families. Trend Micro documented an exploit shotgun strategy that fires more than 50 exploits across 30-plus vendors at internet-facing routers, DVRs, NVRs, CCTV systems, and web servers.

The operators accept noisy failures because volume produces infections faster than precision does.

CloudSEK found RondoDoX distributed alongside Mirai and Morte through the same loader infrastructure, which shows how botnet families share delivery channels instead of competing for devices.

Mirai and Its Descendants

Mirai set the template in 2016 by scanning for default credentials on IoT devices, and its published source code produced a decade of variants.

Current campaigns still run Mirai payloads alongside newer families, a lineage covered in CloudSEK's guide to the Mirai botnet.

Elysium and Operation Endgame

Law enforcement targeted the Elysium botnet alongside the Rhadamanthys infostealer and VenomRAT in November 2025.

Europol reported that the operation took down more than 1,025 servers and seized 20 domains, with the infrastructure tied to hundreds of thousands of infected computers and several million stolen credentials.

How to Detect Botnet Activity on a Corporate Network

To detect botnet activity, security teams watch outbound traffic and name resolution, because infected devices reveal themselves when they call home rather than when they are infected.

Network and Egress Signals

  • Repeated outbound connections to the same external address at fixed intervals, the beaconing pattern that C2 polling creates.
  • Traffic from IoT, printers, or cameras to destinations outside their normal update servers.
  • Sudden outbound volume spikes in NetFlow records, especially UDP floods sourced from internal hosts.
  • Internal devices scanning external IP ranges on telnet, SSH, or HTTP ports.
  • SMTP traffic from hosts that are not mail servers, and SOCKS or HTTP proxy sessions from unexpected devices.

DNS and Name Resolution Signals

Bots relying on domain generation algorithms produce heavy NXDOMAIN volume as they cycle through unregistered names.

Queries for newly registered domains, high-entropy hostnames, and dynamic DNS providers deserve the same scrutiny, and DNS logging feeds these detections into broader security monitoring.

Host and Device Signals

On managed endpoints, look for unsigned processes with network listeners, scheduled tasks pointing at temporary directories, and JSON-RPC calls to mining pools.

Embedded devices give only indirect evidence: degraded performance, reboots into unknown configurations, altered DNS settings, and firmware checksums that no longer match the vendor image.

Intelligence from outside the network closes the loop. Abuse notifications, blocklist entries naming corporate IP ranges, and dark web chatter about the organization's devices all indicate infections that internal tooling has missed.

How to Prevent Botnet Infections in Enterprise Environments

Preventing botnet infections means closing the two doors operators use most: internet-exposed devices with weak credentials and users who run attachments.

  1. Inventory every internet-facing device through external attack surface management, including routers, cameras, and appliances that no asset database tracks.
  2. Replace default and shared credentials on network equipment and IoT hardware, and disable remote administration interfaces that face the public internet.
  3. Patch edge firmware on a short cycle and retire end-of-life devices, since botnet operators specialize in flaws that vendors fixed years ago.
  4. Segment IoT and operational technology away from business systems, a separation that limits damage in IT and OT convergence scenarios.
  5. Filter egress traffic so devices reach only approved destinations and ports, which breaks C2 polling even when infection succeeds.
  6. Apply DNS filtering against newly registered domains, dynamic DNS, and known C2 infrastructure.
  7. Harden email and browsing paths with attachment sandboxing and script controls, the delivery route for loader botnets on workstations.
  8. Enforce multi-factor authentication and monitor for credential exposure so stuffing campaigns fail even with valid passwords.
  9. Contract DDoS protection in advance and rehearse the runbook, because provisioning mitigation during an attack costs hours the business does not have.
  10. Extend access controls to unmanaged devices under a zero trust model, granting them access only to the specific services they require.

Why Botnet Takedowns Rarely End the Threat

Coordinated takedowns disrupt botnets without eliminating them, for reasons built into how these networks are designed.

  • Infected devices stay infected: Seizing servers stops tasking, and the malware remains on millions of devices until owners reimage or replace them.
  • Architecture absorbs losses: Peer-to-peer networks, domain generation algorithms, and fallback channels let operators rebuild control within days.
  • Source code outlives operators: Published code from Mirai and similar families gives every new crew a working foundation.
  • Operators relocate: Arrests reach a fraction of the people involved, and hosting moves to jurisdictions with limited cooperation.
  • Device supply keeps growing: Every quarter adds unpatched cameras, routers, and streaming boxes to the pool of recruitable hardware.

Takedowns still matter, because they impose cost on operators and buy defenders time. The practical lesson for a SOC is that removal of upstream infrastructure never substitutes for finding and cleaning infected devices on its own network.

Tracking Botnet Campaigns With CloudSEK Threat Intelligence

While hunting malicious infrastructure, CloudSEK's TRIAD team found an exposed logger server holding six months of botnet command-and-control activity. The logs named the device types under attack and the injection points being abused.

They exposed the old CVEs in play across WebLogic, WordPress, and vBulletin, plus the drop hosts staging payloads.

Customers whose technology stack matched those vectors were alerted while the campaign was still running. CloudSEK Threat Intelligence produced that warning by tracking the campaign, the malware families behind it, and the exposures that decided which customers were in scope.

Cleaning infected devices stays an internal job. Knowing which malware families are hunting the organization's device types decides where that work starts.

Botnet FAQs

What is a bot herder?

A bot herder, or botmaster, is the operator who controls a botnet, issues commands to infected devices, and rents or sells that capacity to other criminals.

What is the difference between a botnet and a worm?

A worm spreads itself automatically between systems. A botnet is the controlled network that results once infected devices connect to an operator's command infrastructure.

Are botnets illegal?

Yes. Building, operating, renting, or using a botnet constitutes unauthorized access and computer misuse under criminal law in most countries.

Can smart TVs and phones join a botnet?

Yes. Low-cost Android TV boxes and phones running outdated firmware form a large share of current botnets, including the devices behind record DDoS attacks.

Does a factory reset remove botnet malware?

Yes, for most consumer devices, though firmware-resident implants survive a reset. Devices with no vendor patch available need replacement.

Do firewalls stop botnet infections?

Partially. Inbound firewall rules block scanning, and egress filtering blocks C2 traffic, yet neither stops malware delivered through email or software downloads.

Related Posts
What is Malware Sandboxing? How It Works and Its Limits
Malware sandboxing runs suspicious files in an isolated environment to observe their behavior safely. How malware sandboxing works, its types, and evasion.
What is Google Dorking? Operators, Risks, and Defense
Google dorking uses advanced search operators to find sensitive data exposed on the web. How it works, what it exposes, and how to defend against it.
6 Best Digital Risk Protection (DRP) Platforms in 2026
CloudSEK XVigil, Recorded Future, ZeroFox, Rapid7, Group-IB, and Flare cover key DRP needs across external risk, takedown, SOC workflows, scams, and illicit monitoring.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.