ADAM PULSE Knowledge Base
Cybersecurity · Botnets · Automated Attacks

What is a botnet and how does it work?

The short answer: A botnet is a network of compromised computers or other internet connected devices that an attacker can remotely control. Those devices may be used to scan the internet, attempt passwords, spread malware, send spam, overwhelm websites, or attack additional systems.

The disturbing part is that many of the devices participating in a botnet may belong to ordinary businesses or individuals who have no idea their equipment has been compromised.

A computer attacking your firewall may itself be a victim.

A camera scanning your server may belong to a company thousands of miles away.

A router attempting passwords against your VPN may have been compromised months earlier.

That changes how we should think about cyberattacks.

Instead of:

One hacker

↓

One computer

↓

One victim

the attack may look more like:

Attacker

↓

Command infrastructure

↓

Thousands of compromised devices

↓

Thousands or millions of potential targets

This is what gives botnets scale.

And it helps explain why automated attacks appear to come from so many different places.

What Is a Botnet?

The word botnet combines:

bot

and

network.

A bot is a compromised computer or device that can perform instructions provided by someone controlling it.

A botnet is a collection of those compromised devices.

NIST describes a botnet as a network of infected machines that can be remotely managed by a cybercriminal.

The important word is:

Network.

The attacker does not necessarily rely on one computer.

They can potentially control large numbers of devices simultaneously.

What Devices Can Become Part of a Botnet?

Almost any sufficiently capable connected device can potentially become compromised.

People commonly associate botnets with computers.

But modern botnets may involve:

This is why cybersecurity extends far beyond employee laptops.

A camera is a computer.

A router is a computer.

A conference room system is a computer.

A printer is a computer.

If the device has software, credentials, network connectivity, and processing capability, it deserves cybersecurity consideration.

How Does a Device Become Part of a Botnet?

There is no single method.

Attackers may compromise devices through weaknesses such as:

Once the attacker gains sufficient control, malware or other malicious components may establish a way for the device to receive instructions.

The device is now potentially part of the attacker's infrastructure.

What Happens After a Device Is Compromised?

The victim may expect something dramatic.

A warning screen.

Files disappearing.

A ransom demand.

A computer becoming unusable.

But attackers do not always want the owner to notice.

A botnet is more useful if the compromised device continues operating normally.

The attacker may want:

The owner to keep paying for the internet connection.

The device to remain online.

The power to remain on.

Nobody to investigate.

The compromised system can then quietly perform tasks in the background.

Why Would an Attacker Want My Computer in a Botnet?

Because your computer provides resources.

Those resources can include:

From the attacker's perspective, compromising thousands of computers means acquiring thousands of pieces of infrastructure without purchasing them.

The victims pay for:

the hardware

the electricity

the internet connection

while the attacker uses the resources.

That is an extremely attractive criminal business model.

What Can Botnets Be Used For?

Botnets can support many forms of malicious activity.

Common uses may include:

Different botnets may be designed for different objectives.

Some may perform several functions.

What Is a Distributed Denial of Service Attack?

A distributed denial of service attack, commonly called a DDoS attack, attempts to overwhelm a system, website, application, or network with traffic or requests.

The word distributed is important.

Instead of traffic coming from one machine, it may come from large numbers of systems.

Imagine a business that normally receives 1,000 legitimate visitors per day.

Suddenly:

100,000 systems

begin requesting resources simultaneously.

The service may become overwhelmed.

Legitimate users can no longer access it.

This is one reason botnets are so useful for DDoS attacks.

They provide distribution and scale.

Why Is a Botnet Better Than One Attacking Computer?

Suppose an attacker uses one computer to send malicious traffic.

A defender identifies the source IP address.

The defender blocks it.

Problem solved.

Now imagine:

10,000 compromised devices

are participating.

The defender blocks one.

There are still:

9,999.

This illustrates why simple IP blocking has limitations against distributed attacks.

Blocking malicious sources can still be useful.

But it does not necessarily address the underlying threat.

Why Do Botnet Attacks Come From So Many Different Countries?

Because the compromised devices may be located around the world.

The botnet controller might be located in one country.

The victims whose devices are compromised may be located in dozens of others.

The businesses being attacked may be located somewhere else entirely.

This creates an important cybersecurity lesson:

> The geographic location of an attacking IP address does not necessarily tell you where the person controlling the attack is located.

The device generating the traffic may itself be compromised.

Does That Mean Geoblocking Is Useless?

No.

Geographic restrictions can sometimes reduce unnecessary exposure when a business has no legitimate reason to receive certain types of traffic from particular regions.

But geography should not become the entire security model.

An attacker can potentially use compromised devices located in:

A malicious connection originating domestically is still malicious.

Geographic filtering can reduce noise.

It cannot establish trust by itself.

How Do Botnets Find New Victims?

This connects directly to the earlier article in this series:

How Do Hackers Find Vulnerable Computers?

Botnets themselves can participate in discovery.

Compromised devices can scan internet addresses looking for:

When another vulnerable device is found, the botnet may attempt to compromise it.

If successful, the new device can potentially become another bot.

The network grows.

Can a Botnet Spread Itself?

Some malware can automatically identify and attempt to compromise additional systems.

That creates a self propagating effect.

The sequence may look like:

Compromise device

↓

Scan for more devices

↓

Find vulnerable device

↓

Exploit vulnerability

↓

Install malware

↓

New device joins botnet

↓

Repeat

Automation allows malicious infrastructure to grow without a human manually compromising every machine.

Why Are Default Passwords So Important to Botnets?

Default credentials can give automated attackers an easy entry point.

Imagine a bot scanning the internet for a particular type of camera.

The software discovers one.

It tries:

admin

plus the manufacturer's historical default password.

If access succeeds, the device may potentially be compromised.

No password cracking was required.

No employee had to click anything.

The device was simply:

reachable

and

poorly secured.

This is exactly why default password management matters.

Why Are Cameras and IoT Devices Attractive Botnet Targets?

IoT devices often operate very differently from employee computers.

A laptop receives attention.

Employees use it every day.

Endpoint security may be installed.

Updates may be managed.

A camera may be installed on a wall and ignored for five years.

That creates potential problems.

The device may have:

And unlike a laptop, nobody may notice strange background activity.

Why Would Nobody Notice a Compromised Camera?

Because the camera may continue working.

It still displays video.

The recording still works.

The lights still blink.

There may be no obvious indication that something is wrong.

Meanwhile the device could potentially be generating network traffic or communicating with external infrastructure.

This reinforces a major theme of this series:

Working does not necessarily mean secure.

A device can perform its intended function while simultaneously being compromised.

Can Routers Become Part of Botnets?

Yes.

Routers are especially significant because they sit directly on networks and frequently remain powered on continuously.

They can also be overlooked.

A business might replace employee laptops every few years while leaving network infrastructure operating much longer.

Routers require:

The FTC's current small business cybersecurity guidance specifically recommends changing default router credentials, turning off unnecessary remote management, maintaining secure wireless settings, and limiting devices on the business network.

Why Are Old Devices a Cybersecurity Problem?

Older equipment may eventually stop receiving security updates.

The device may still work perfectly.

That creates a dangerous temptation:

“Why replace it? It still works.”

But operational functionality and security support are different.

Ask:

Is the device still supported by the manufacturer?

Does it receive security updates?

Is its firmware current?

Are known vulnerabilities documented?

Can modern authentication methods be used?

A device can be operationally functional and still represent unacceptable security risk.

Can Servers Become Bots?

Yes.

Compromised servers can be particularly valuable because they may provide attackers with:

A compromised server might therefore be used as:

This is another reason internet exposed servers deserve aggressive security management.

What Is Command and Control?

Botnets need a way to receive instructions.

This mechanism is commonly called command and control, often abbreviated C2 or C&C.

The attacker uses command infrastructure to instruct compromised systems what to do.

For example:

Scan these addresses.

Attack this website.

Download this file.

Send this traffic.

Try these credentials.

Update the malware.

The compromised devices then execute the instructions.

Does Every Botnet Use One Command Server?

No.

Botnet architectures vary.

Some use centralized infrastructure.

Others may use more distributed approaches.

Attackers may also design infrastructure to make shutdown and investigation more difficult.

The important concept for a business owner is not the specific technical architecture.

It is:

Compromised devices can receive instructions remotely and act together.

How Can Cybersecurity Teams Detect Command and Control Activity?

Potential clues can include unusual communications between an internal device and external infrastructure.

Security technologies may examine:

An unusual connection does not automatically prove command and control activity.

But context can make it more significant.

For example:

Unknown device

plus

repeated communication to known malicious infrastructure

plus

unexpected outbound traffic

deserves investigation.

Why Does Outbound Traffic Matter So Much?

Businesses naturally focus on inbound attacks.

Someone is trying to get in.

But once a device is compromised, outbound communications can become extremely important.

The device may need to:

Receive instructions.

Report status.

Download additional malware.

Send stolen information.

Participate in other attacks.

That means cybersecurity monitoring should ask both:

What is trying to enter?

and

What is trying to leave?

Can a Compromised Business Be Used to Attack Someone Else?

Yes.

This is one of the most uncomfortable aspects of botnets.

Your company may not be the final victim.

A compromised device within your business could potentially be used to attack:

Your infrastructure can become part of someone else's attack.

This gives cybersecurity a second dimension.

You are protecting your business.

But you are also preventing your technology from being used against others.

What Is an Attack Proxy?

Attackers may route malicious activity through compromised infrastructure.

The compromised device acts as an intermediary between the attacker and the target.

This can help obscure the attacker's true location.

To the target, the traffic appears to originate from the compromised system.

This is another reason IP address attribution is complicated.

The source you see may not be the source controlling the activity.

Why Blocking One Malicious IP Address Is Not Enough

This is one of the most important practical lessons from botnets.

Suppose an organization detects repeated attacks from:

IP Address A.

The firewall blocks it.

Excellent.

Five minutes later:

IP Address B

begins the same activity.

Then:

C.

D.

E.

The organization can continue blocking addresses forever.

Or it can ask a better question:

What are these systems trying to reach?

If all of them are attempting the same exposed service, perhaps the root problem is the exposed service.

The better response may involve:

Blocking sources is useful.

Reducing opportunity is stronger.

What Is Threat Intelligence?

Threat intelligence provides information about known or suspected malicious activity.

It may include indicators such as:

Organizations can use this information to add context to events.

For example:

Unknown IP attempted to connect

is one piece of information.

Unknown IP attempted to connect and is associated with known malicious scanning activity

provides more context.

But threat intelligence should not be treated as perfect truth.

Can an IP Address Have a Bad Reputation?

Yes.

Security providers maintain reputation systems that evaluate internet infrastructure based on observed activity.

An address may be associated with:

This can help organizations prioritize investigation.

But IP reputation has limitations.

Addresses change ownership.

Cloud infrastructure is shared.

Compromised devices can be cleaned.

Threat information becomes stale.

A reputation score should be treated as:

a signal

not

a verdict.

What Is a False Positive in Threat Intelligence?

A legitimate address can sometimes appear suspicious.

For example:

A cybersecurity researcher may perform large scale scanning.

A cloud provider may host both legitimate and malicious customers.

A previously compromised system may have been cleaned.

An address may have changed owners.

This is why threat intelligence should be combined with:

Cybersecurity improves when multiple signals agree.

How Can I Tell if My Computer Is Part of a Botnet?

There is no single universal symptom.

Potential warning signs could include:

But many of these conditions can also have legitimate explanations.

Professional investigation may be necessary.

The absence of symptoms does not prove a device is clean.

Can My Router Be Compromised Without Me Knowing?

Potentially.

A router may continue routing internet traffic while also being compromised.

The same can apply to other infrastructure.

That is why businesses should monitor more than:

“Is the internet working?”

They should also ask:

Is the router current?

Is its configuration expected?

Are there unknown administrators?

Is remote management enabled unnecessarily?

Is it communicating in unexpected ways?

Does the manufacturer still support it?

Availability is not the same thing as security.

How Do I Prevent My Devices From Becoming Part of a Botnet?

There is no single control.

A layered approach is strongest.

1. Change Default Passwords

Do not leave manufacturer defaults in place.

2. Use Unique Credentials

Avoid reusing passwords.

3. Enable MFA

Especially for administrative and remote access.

4. Patch Devices

Keep firmware, software, applications, and operating systems current.

5. Remove Unnecessary Internet Exposure

Do not expose services simply for convenience.

6. Disable Unnecessary Remote Management

Restrict administrative access.

7. Inventory Devices

Know what is connected.

8. Replace Unsupported Equipment

Do not rely indefinitely on technology that no longer receives security fixes.

9. Segment Networks

Separate IoT and other devices where appropriate.

10. Use Endpoint Security

Protect supported computers and servers.

11. Monitor Network Activity

Pay attention to unexpected inbound and outbound behavior.

12. Investigate Alerts

Do not assume security tools will solve everything automatically.

The FTC's current small business guidance reflects many of these same practices, including hardware and software inventory, MFA, patching, changing default manufacturer passwords, limiting network access, separating guest networks, and maintaining an incident response plan.

Why Asset Inventory Is a Botnet Defense

At first this may sound unrelated.

What does inventory have to do with malware?

Everything.

Imagine seeing an unfamiliar device generating unusual traffic.

You ask:

What is this?

Nobody knows.

Who installed it?

Nobody knows.

Who manages it?

Nobody knows.

When was it patched?

Nobody knows.

What is the password?

Nobody knows.

That is a security problem before we even determine whether the device is compromised.

The FTC's current small business guidance, built around NIST CSF 2.0, specifically recommends creating and maintaining an inventory of hardware, software, services, applications, and other technology the business relies upon.

You cannot confidently identify an unauthorized device if you do not know what an authorized environment looks like.

How Network Segmentation Helps

Suppose a security camera becomes compromised.

If the camera network can communicate freely with:

Accounting computers

file servers

employee laptops

point of sale equipment

the compromise may create broader risk.

Now consider a segmented architecture.

The cameras can communicate only with the systems they legitimately require.

A compromise still matters.

But the potential movement is constrained.

This is the principle of containment.

A device should not automatically gain access to everything simply because it is inside the building.

Should IoT Devices Be on a Separate Network?

Often, separating IoT and similar equipment from sensitive business systems can reduce risk.

The exact design depends on the organization.

But asking the question is valuable:

Why does this device need access to that system?

A security camera may need:

It probably does not need unrestricted access to:

Segmentation makes those boundaries possible.

Can Antivirus Detect Botnet Malware?

Endpoint security may detect malware associated with botnets.

But no single security technology sees everything.

Some devices cannot run conventional endpoint protection at all.

You may be able to install advanced endpoint protection on a Windows server.

You probably cannot install the same software on every:

That is why network level visibility is also important.

Why Network Monitoring Matters for IoT Security

Many IoT devices have limited local security visibility.

Network behavior can provide useful clues.

Ask:

Is the device online?

What does it communicate with?

Did that behavior change?

Is it transferring unexpected data?

Did it begin contacting new destinations?

Is it generating unusual traffic?

Again, no single behavior automatically proves compromise.

But monitoring provides evidence for investigation.

What Happens if My Business Is Participating in a DDoS Attack Without Knowing It?

That should be treated as a potential security incident.

A device generating malicious traffic may indicate compromise.

The organization may need to:

Do not simply block outbound traffic and assume the underlying problem is solved.

The malicious communication may be the symptom.

The compromise is the root problem.

What Should I Do if I Suspect a Device Is Part of a Botnet?

The appropriate response depends on the device and circumstances.

A general incident response process may involve:

Identify

Determine which device is generating suspicious activity.

Contain

Limit the device's ability to communicate where appropriate.

Preserve Information

Retain relevant logs and evidence.

Investigate

Determine what occurred and how.

Remediate

Remove malware, fix vulnerabilities, reset credentials, update software, or replace equipment.

Verify

Confirm that malicious activity has stopped.

Review

Determine whether similar devices may have the same weakness.

That last step is critical.

If one camera was compromised because all cameras use the same default password, cleaning one camera does not solve the organizational problem.

One Compromised Device Should Trigger a Bigger Question

Suppose one router is compromised.

Do not only ask:

“How do we fix this router?”

Ask:

“Do our other routers have the same configuration?”

If one camera uses default credentials:

Do all cameras use them?

If one server missed a patch:

Did other servers miss it too?

If one vendor account was forgotten:

Are there others?

A security incident should improve the entire environment.

Botnets Demonstrate Why Cybersecurity Is a Scale Problem

Attackers use automation because manual activity does not scale.

Businesses should think the same way about defense.

Imagine an organization with:

50 locations

500 network devices

1,000 users

Manual inspection alone cannot provide continuous awareness.

Defenders need technology that can help:

Then people can investigate what matters.

This is the same principle we have seen throughout this series:

> Attackers automate scale. Defenders need to automate awareness.

Where USA Telecom and ADAM Fit

Botnets reinforce why network visibility matters.

USA Telecom and ADAM are not a replacement for:

Those technologies provide specialized security capabilities.

But an organization also needs operational awareness across its infrastructure.

ADAM can support the broader process of understanding:

What is connected?

What is reachable?

What changed?

What stopped responding?

What location is affected?

What network path is involved?

Does the activity require investigation?

That visibility helps shorten the gap between:

Something happened

and

Someone noticed.

Monitoring Is Especially Important in Distributed Businesses

Consider a company operating 100 locations.

Each location may contain:

That can quickly become thousands of devices.

A business should be able to answer:

Which devices are supposed to exist?

Which are online?

Which are unsupported?

Which locations changed?

Which equipment is behaving unexpectedly?

Who owns each device?

Without centralized visibility, configuration inconsistencies become easier to miss.

Attackers benefit from inconsistency.

Standardization helps defenders.

Botnets Also Demonstrate Why Root Cause Matters

Suppose your firewall receives attacks from 5,000 different IP addresses.

One response would be:

Block 5,000 IP addresses.

But why are they all attempting the same service?

Maybe:

The service is unnecessarily exposed.

The software is outdated.

A login interface should be restricted.

MFA is missing.

The firewall rule is too broad.

The attack traffic is the symptom.

The exposure may be the root cause.

This is where security becomes architecture rather than whack a mole.

20 Questions Every Business Should Ask About Connected Devices

1. Do we know every device connected to our network?

2. Who owns each device?

3. Who manages it?

4. Were the default credentials changed?

5. Is the firmware current?

6. Is the manufacturer still supporting it?

7. Does the device require internet access?

8. Does it require inbound internet access?

9. Is remote administration enabled?

10. Does remote administration actually need to be enabled?

11. Can MFA be enabled?

12. Is the device on the appropriate network segment?

13. What other systems can it communicate with?

14. Are IoT devices separated from sensitive business systems?

15. Can we identify unusual outbound communication?

16. Would we know if the device stopped responding?

17. Are security and availability logs retained?

18. What happens when a device reaches end of support?

19. What is our process for removing old equipment?

20. Who investigates when something behaves unexpectedly?

Those questions turn IoT and network security from:

“Is the device working?”

into:

“Is the device known, supported, secured, and behaving as expected?”

The Better Question Is Not “Who Is Attacking Us?”

When an organization sees suspicious traffic, the natural question is:

“Who is this?”

That can be useful.

But botnets demonstrate why attribution can be complicated.

The IP address may belong to another victim.

The attacking device may be compromised.

The person directing the attack may be somewhere entirely different.

So ask additional questions:

What are they trying to reach?

Why is it reachable?

Was anything successful?

What vulnerability are they testing?

Can we reduce the exposure?

Are similar systems affected?

Are we monitoring the right things?

The identity of the attacker matters.

But reducing the opportunity often matters more.

Key Takeaway

A botnet changes the scale of cybercrime.

An attacker does not necessarily need:

one powerful computer.

They can potentially control:

thousands of ordinary computers and devices.

Those devices may belong to:

businesses

families

schools

government organizations

cloud customers

people who have no idea they are participating in an attack.

That is why cyberattacks can appear to come from everywhere.

And it is why simply blocking one malicious address is rarely enough.

Businesses should focus on the fundamentals:

Know what is connected.

Change default credentials.

Patch devices.

Replace unsupported equipment.

Reduce unnecessary exposure.

Segment networks.

Protect administrative access.

Monitor inbound activity.

Monitor outbound activity.

Investigate anomalies.

And remember:

> The computer attacking you may itself be a victim.

The important question is not only:

“Who should we block?”

It is:

“What are they trying to exploit, and why do they have the opportunity to try?”

Frequently asked questions

What is a botnet?

A botnet is a network of compromised computers or devices that can be remotely controlled and coordinated by an attacker. NIST describes botnets as networks of infected machines that criminals can remotely manage.

What does botnet mean?

The term combines “bot,” meaning an automated or remotely controlled system, with “network.”

How does a botnet work?

Attackers compromise multiple devices and establish a mechanism for remotely instructing them. The devices can then perform coordinated activities such as scanning, sending spam, attempting credentials, spreading malware, or participating in DDoS attacks.

What devices can become part of a botnet?

Computers, servers, routers, cameras, IoT equipment, network devices, and other internet connected systems can potentially become compromised.

Can a security camera become part of a botnet?

Potentially, yes. Connected cameras are computers running software and may become vulnerable if they use weak credentials, outdated firmware, unnecessary internet exposure, or exploitable software.

Can a router become part of a botnet?

Yes. Routers run software and can become targets if they are poorly configured, use weak credentials, expose unnecessary management services, or contain exploitable vulnerabilities.

Can a server become part of a botnet?

Yes. Compromised servers may provide attackers with processing power, bandwidth, storage, and continuous internet connectivity.

What do botnets do?

Botnets may be used for DDoS attacks, scanning, password attacks, spam, malware distribution, fraud, proxy services, and other malicious activities.

What is a DDoS attack?

A distributed denial of service attack uses traffic from many systems to overwhelm a network, website, application, or service so legitimate users cannot access it.

Why do botnet attacks come from many IP addresses?

Because the attack can be distributed across large numbers of compromised devices located on different networks and in different countries.

Is the IP address attacking me the hacker's IP address?

Not necessarily. The source may be a compromised device, proxy, cloud server, or other intermediary being used by the attacker.

Should I block malicious IP addresses?

Blocking known malicious sources can be useful, but it is not a complete defense against botnets because attackers may use many different addresses. Organizations should also reduce exposure, patch vulnerabilities, use MFA, and investigate the underlying target.

How do botnets spread?

Some botnets can search for and exploit additional vulnerable devices, allowing the malicious network to grow automatically.

Do botnets use default passwords?

Weak or default credentials can be one method attackers use to compromise devices.

What is botnet command and control?

Command and control refers to the infrastructure or mechanisms attackers use to communicate with compromised devices and issue instructions.

How do I know if my computer is part of a botnet?

Possible indicators include malware detections, unusual outbound traffic, unexplained network activity, unexpected processor use, or communications with malicious infrastructure. Professional investigation may be needed because these indicators can also have legitimate causes.

How do I know if my router is compromised?

Signs may include unexplained configuration changes, unexpected accounts, unusual network communications, security alerts, or other anomalous behavior. The router should also be checked for current firmware, supported lifecycle status, secure administration, and expected configuration.

Can antivirus remove botnet malware?

Endpoint security may detect and remove some botnet malware, but no single product detects every threat, and many IoT or network devices cannot run traditional antivirus.

How can I prevent my devices from becoming bots?

Change default credentials, use MFA where supported, patch devices, remove unnecessary internet exposure, disable unnecessary remote management, segment networks, inventory equipment, replace unsupported hardware, and monitor for unusual behavior.

Are botnets only a problem for large companies?

No. Automated attacks can discover vulnerable equipment regardless of the size of the organization operating it.

Can my business accidentally attack another company?

If one of your systems becomes compromised and is incorporated into malicious infrastructure, attackers may potentially use it to generate traffic or attacks against other systems.

What should I do if a device is participating in a botnet?

Treat it as a possible security incident. Identify and contain the device, preserve relevant information, investigate the compromise, remove malicious software or replace the equipment, patch vulnerabilities, reset affected credentials, and determine whether similar devices are exposed.

Sources

Editorial note

Cybersecurity risk and the controls appropriate to it vary by organization. Evaluate these recommendations against your own technology environment, business requirements, regulatory obligations, threat profile and risk tolerance.

USA Telecom Consulting LLC is a Service-Disabled Veteran-Owned Small Business running a 24/7 NOC. We monitor networks, circuits and firewalls for regulated and defense-supply-chain organizations.

← More from the ADAM Pulse Knowledge Base