Cyber Threats & Countermeasures

Botnet

About 4 min read

What Is a Botnet

A botnet is a network made up of many computers and devices that have been infected with malware and placed under an attacker's remote control. Each infected device is called a bot or a zombie, and it follows the attacker's orders while its owner never notices.

Botnets range from a few thousand to several million devices, and because the infected machines can be driven as a single unit, they are abused for DDoS attacks, bulk delivery of spam email, cryptocurrency mining, and theft of personal information. An attacker can mount a large-scale attack without preparing any infrastructure, and there are also arrangements in which the pooled processing power is sold to third parties, such as the services known as booters or stressers that carry out DDoS attacks on request.

C&C Servers and Command Architecture

At the heart of a botnet sits the C&C (Command and Control) server. The attacker uses it to issue orders to the whole population of infected devices at once.

Centralized (Client-Server)
One C&C server, or a small number of them, controls every bot. The structure is simple and responses are fast, but if the C&C server is identified and cut off, the entire botnet is neutralized.
Decentralized (P2P)
Bots relay orders to one another over a P2P network. Because there is no central server, a takedown is harder to carry out. GameOver ZeuS, known as the P2P form of ZeuS, and Hajime, which spread through IoT equipment, both adopted this design.
Domain Generation Algorithm (DGA)
Bots mechanically generate candidate domain names from the date and time, then look for the C&C server's domain among them. This makes it harder for defenders to secure the domains in advance. With Conficker, early variants generated 250 candidate domains a day across five TLDs, and later variants scaled up to trying 500 out of 50,000 candidates every day.

C&C traffic can also be hidden inside social media posts or encrypted messaging services. Because it looks like a connection to a legitimate service, blocking based on destination IP addresses or domain names becomes less effective.

One example of a takedown is Operation Tovar, in which law enforcement agencies from 13 countries worked together with private companies to shut down GameOver ZeuS in June 2014. Even so, taking out the C&C servers leaves the infected devices in place, and they can be regrouped through another command channel, so the same infected base is reused unless the command path is cut and the devices are cleaned at the same time.

How Botnets Are Exploited

  • DDoS Attacks: Tens of thousands to millions of bots send requests to a target server all at once and bring the service down. On October 21, 2016, the DNS provider Dyn was hit by three waves of attacks from IoT devices infected with Mirai, leaving Twitter, Netflix, Reddit, and many other services unreachable.
  • Spam and Phishing Campaigns: By rotating through the IP addresses of the bots, the attacker delivers mail in bulk while avoiding blacklisting of the sending source.
  • Credential Stuffing: Using lists of leaked account information, bots try to log in automatically to many services. Botnets serve as the main platform for carrying out these attacks.
  • Cryptojacking: The CPU and GPU resources of infected devices are used without permission to mine cryptocurrency into the attacker's wallet. The victim pays the electricity bill and absorbs the wear on the hardware.

The Mirai Botnet - A Turning Point for IoT Security

Mirai, which appeared in 2016, is the case that showed the world what botnets can do. Its targets were not PCs but IoT equipment such as home routers, network cameras, and DVRs. Mirai scanned Telnet ports 23 and 2323 indiscriminately and tried to log in to any device that answered using default user names and passwords.

CISA alert TA16-288A in the United States records that Mirai tried only 62 sets of commonly used default credentials, and that this short dictionary alone was enough to break into equipment on the scale of hundreds of thousands of devices. The source code was published at the end of September 2016, and many variants were derived from it. As long as devices are installed with their default passwords intact and equipment ships without any means of updating it, the same technique keeps working. The incident showed that the settings of small devices sitting in homes and offices bear directly on the stability of the internet as a whole.

How to Protect Against Botnet Infection

Preventing botnet infection calls for layered measures suited to each type of device.

  • Keep OS and Firmware Updated: The basic measure against infection through vulnerabilities. Update the firmware of routers and IoT devices on a regular basis, not just PCs.
  • Change Default Passwords: The lesson of Mirai. On routers, network cameras, NAS units, and every other device that connects to the network, replace the factory-set password with a strong one.
  • Close Unnecessary Ports: Close ports used for remote access from outside, such as Telnet (port 23) and SSH (port 22), when they are not needed.
  • Configure Your Firewall: Detect and block suspicious outbound traffic, such as connections to a C&C server.
  • Monitor Network Traffic: Put in place a mechanism that detects traffic patterns out of the ordinary, such as heavy communication in the middle of the night or periodic connections to unknown external IP addresses.

In corporate environments, using network segmentation to separate IoT devices from the business network is also effective. Even if an infection occurs, the damage can be kept from spreading.

Common Misconceptions

Only PCs get infected by botnets
Since Mirai, IoT devices (routers, network cameras, smart appliances) have become primary botnet targets. These devices often lack timely security updates and can be more vulnerable than PCs. Smartphones have also been reported as botnet nodes through malicious apps.
You would notice immediately if your device were part of a botnet
Bots are designed to remain invisible. They keep CPU and bandwidth usage low and behave normally until they receive an attack command. Most infected devices appear to function perfectly under everyday use.
Antivirus software provides complete protection
While antivirus is valuable for PCs, most IoT devices cannot run security software at all. Firmware updates, password changes, and network-level defenses are essential for devices beyond traditional computers.
Share

Related Terms

Related Articles