What is a botnet and how does it work?
The short answer: A botnet is a network of compromised computers or other internet connected devices that an attacker can remotely control. Those devices may be used to scan the internet, attempt passwords, spread malware, send spam, overwhelm websites, or attack additional systems.
The disturbing part is that many of the devices participating in a botnet may belong to ordinary businesses or individuals who have no idea their equipment has been compromised.
A computer attacking your firewall may itself be a victim.
A camera scanning your server may belong to a company thousands of miles away.
A router attempting passwords against your VPN may have been compromised months earlier.
That changes how we should think about cyberattacks.
Instead of:
One hacker
↓
One computer
↓
One victim
the attack may look more like:
Attacker
↓
Command infrastructure
↓
Thousands of compromised devices
↓
Thousands or millions of potential targets
This is what gives botnets scale.
And it helps explain why automated attacks appear to come from so many different places.
What Is a Botnet?
The word botnet combines:
bot
and
network.
A bot is a compromised computer or device that can perform instructions provided by someone controlling it.
A botnet is a collection of those compromised devices.
NIST describes a botnet as a network of infected machines that can be remotely managed by a cybercriminal.
The important word is:
Network.
The attacker does not necessarily rely on one computer.
They can potentially control large numbers of devices simultaneously.
What Devices Can Become Part of a Botnet?
Almost any sufficiently capable connected device can potentially become compromised.
People commonly associate botnets with computers.
But modern botnets may involve:
- Desktop computers
- Laptops
- Servers
- Routers
- Firewalls
- Security cameras
- Network video recorders
- Internet of Things devices
- Network storage devices
- Smart home equipment
- Embedded systems
- Cloud servers
This is why cybersecurity extends far beyond employee laptops.
A camera is a computer.
A router is a computer.
A conference room system is a computer.
A printer is a computer.
If the device has software, credentials, network connectivity, and processing capability, it deserves cybersecurity consideration.
How Does a Device Become Part of a Botnet?
There is no single method.
Attackers may compromise devices through weaknesses such as:
- Default passwords
- Weak credentials
- Known vulnerabilities
- Unpatched software
- Exposed services
- Malicious downloads
- Phishing
- Poorly secured remote access
- Vulnerable applications
- Misconfigurations
Once the attacker gains sufficient control, malware or other malicious components may establish a way for the device to receive instructions.
The device is now potentially part of the attacker's infrastructure.
What Happens After a Device Is Compromised?
The victim may expect something dramatic.
A warning screen.
Files disappearing.
A ransom demand.
A computer becoming unusable.
But attackers do not always want the owner to notice.
A botnet is more useful if the compromised device continues operating normally.
The attacker may want:
The owner to keep paying for the internet connection.
The device to remain online.
The power to remain on.
Nobody to investigate.
The compromised system can then quietly perform tasks in the background.
Why Would an Attacker Want My Computer in a Botnet?
Because your computer provides resources.
Those resources can include:
- Internet connectivity
- An IP address
- Processing power
- Memory
- Bandwidth
- Storage
- Geographic presence
- Access to other systems
From the attacker's perspective, compromising thousands of computers means acquiring thousands of pieces of infrastructure without purchasing them.
The victims pay for:
the hardware
the electricity
the internet connection
while the attacker uses the resources.
That is an extremely attractive criminal business model.
What Can Botnets Be Used For?
Botnets can support many forms of malicious activity.
Common uses may include:
- Distributed denial of service attacks
- Internet scanning
- Password attacks
- Malware distribution
- Spam
- Phishing
- Fraud
- Credential attacks
- Proxy services
- Cryptocurrency mining
- Attacks against additional systems
Different botnets may be designed for different objectives.
Some may perform several functions.
What Is a Distributed Denial of Service Attack?
A distributed denial of service attack, commonly called a DDoS attack, attempts to overwhelm a system, website, application, or network with traffic or requests.
The word distributed is important.
Instead of traffic coming from one machine, it may come from large numbers of systems.
Imagine a business that normally receives 1,000 legitimate visitors per day.
Suddenly:
100,000 systems
begin requesting resources simultaneously.
The service may become overwhelmed.
Legitimate users can no longer access it.
This is one reason botnets are so useful for DDoS attacks.
They provide distribution and scale.
Why Is a Botnet Better Than One Attacking Computer?
Suppose an attacker uses one computer to send malicious traffic.
A defender identifies the source IP address.
The defender blocks it.
Problem solved.
Now imagine:
10,000 compromised devices
are participating.
The defender blocks one.
There are still:
9,999.
This illustrates why simple IP blocking has limitations against distributed attacks.
Blocking malicious sources can still be useful.
But it does not necessarily address the underlying threat.
Why Do Botnet Attacks Come From So Many Different Countries?
Because the compromised devices may be located around the world.
The botnet controller might be located in one country.
The victims whose devices are compromised may be located in dozens of others.
The businesses being attacked may be located somewhere else entirely.
This creates an important cybersecurity lesson:
> The geographic location of an attacking IP address does not necessarily tell you where the person controlling the attack is located.
The device generating the traffic may itself be compromised.
Does That Mean Geoblocking Is Useless?
No.
Geographic restrictions can sometimes reduce unnecessary exposure when a business has no legitimate reason to receive certain types of traffic from particular regions.
But geography should not become the entire security model.
An attacker can potentially use compromised devices located in:
- Your country
- Your state
- Your city
- The same cloud providers your business uses
A malicious connection originating domestically is still malicious.
Geographic filtering can reduce noise.
It cannot establish trust by itself.
How Do Botnets Find New Victims?
This connects directly to the earlier article in this series:
How Do Hackers Find Vulnerable Computers?
Botnets themselves can participate in discovery.
Compromised devices can scan internet addresses looking for:
- Open ports
- Remote access systems
- Routers
- Cameras
- Servers
- Known vulnerabilities
- Default credentials
- Weak passwords
When another vulnerable device is found, the botnet may attempt to compromise it.
If successful, the new device can potentially become another bot.
The network grows.
Can a Botnet Spread Itself?
Some malware can automatically identify and attempt to compromise additional systems.
That creates a self propagating effect.
The sequence may look like:
Compromise device
↓
Scan for more devices
↓
Find vulnerable device
↓
Exploit vulnerability
↓
Install malware
↓
New device joins botnet
↓
Repeat
Automation allows malicious infrastructure to grow without a human manually compromising every machine.
Why Are Default Passwords So Important to Botnets?
Default credentials can give automated attackers an easy entry point.
Imagine a bot scanning the internet for a particular type of camera.
The software discovers one.
It tries:
admin
plus the manufacturer's historical default password.
If access succeeds, the device may potentially be compromised.
No password cracking was required.
No employee had to click anything.
The device was simply:
reachable
and
poorly secured.
This is exactly why default password management matters.
Why Are Cameras and IoT Devices Attractive Botnet Targets?
IoT devices often operate very differently from employee computers.
A laptop receives attention.
Employees use it every day.
Endpoint security may be installed.
Updates may be managed.
A camera may be installed on a wall and ignored for five years.
That creates potential problems.
The device may have:
- Old firmware
- Default credentials
- Unnecessary remote access
- Limited monitoring
- No obvious owner
- Poor documentation
And unlike a laptop, nobody may notice strange background activity.
Why Would Nobody Notice a Compromised Camera?
Because the camera may continue working.
It still displays video.
The recording still works.
The lights still blink.
There may be no obvious indication that something is wrong.
Meanwhile the device could potentially be generating network traffic or communicating with external infrastructure.
This reinforces a major theme of this series:
Working does not necessarily mean secure.
A device can perform its intended function while simultaneously being compromised.
Can Routers Become Part of Botnets?
Yes.
Routers are especially significant because they sit directly on networks and frequently remain powered on continuously.
They can also be overlooked.
A business might replace employee laptops every few years while leaving network infrastructure operating much longer.
Routers require:
- Secure credentials
- Current software
- Controlled management access
- Appropriate configuration
- Monitoring
- Lifecycle management
The FTC's current small business cybersecurity guidance specifically recommends changing default router credentials, turning off unnecessary remote management, maintaining secure wireless settings, and limiting devices on the business network.
Why Are Old Devices a Cybersecurity Problem?
Older equipment may eventually stop receiving security updates.
The device may still work perfectly.
That creates a dangerous temptation:
“Why replace it? It still works.”
But operational functionality and security support are different.
Ask:
Is the device still supported by the manufacturer?
Does it receive security updates?
Is its firmware current?
Are known vulnerabilities documented?
Can modern authentication methods be used?
A device can be operationally functional and still represent unacceptable security risk.
Can Servers Become Bots?
Yes.
Compromised servers can be particularly valuable because they may provide attackers with:
- High speed internet connections
- Significant processing resources
- Continuous uptime
- Cloud infrastructure
- Large bandwidth allocations
A compromised server might therefore be used as:
- A scanner
- A malware host
- A command server
- A proxy
- An attack platform
- A DDoS participant
This is another reason internet exposed servers deserve aggressive security management.
What Is Command and Control?
Botnets need a way to receive instructions.
This mechanism is commonly called command and control, often abbreviated C2 or C&C.
The attacker uses command infrastructure to instruct compromised systems what to do.
For example:
Scan these addresses.
Attack this website.
Download this file.
Send this traffic.
Try these credentials.
Update the malware.
The compromised devices then execute the instructions.
Does Every Botnet Use One Command Server?
No.
Botnet architectures vary.
Some use centralized infrastructure.
Others may use more distributed approaches.
Attackers may also design infrastructure to make shutdown and investigation more difficult.
The important concept for a business owner is not the specific technical architecture.
It is:
Compromised devices can receive instructions remotely and act together.
How Can Cybersecurity Teams Detect Command and Control Activity?
Potential clues can include unusual communications between an internal device and external infrastructure.
Security technologies may examine:
- Destination addresses
- Domains
- Communication patterns
- Traffic frequency
- Known threat intelligence
- Endpoint behavior
- DNS activity
- Application behavior
An unusual connection does not automatically prove command and control activity.
But context can make it more significant.
For example:
Unknown device
plus
repeated communication to known malicious infrastructure
plus
unexpected outbound traffic
deserves investigation.
Why Does Outbound Traffic Matter So Much?
Businesses naturally focus on inbound attacks.
Someone is trying to get in.
But once a device is compromised, outbound communications can become extremely important.
The device may need to:
Receive instructions.
Report status.
Download additional malware.
Send stolen information.
Participate in other attacks.
That means cybersecurity monitoring should ask both:
What is trying to enter?
and
What is trying to leave?
Can a Compromised Business Be Used to Attack Someone Else?
Yes.
This is one of the most uncomfortable aspects of botnets.
Your company may not be the final victim.
A compromised device within your business could potentially be used to attack:
- Another business
- A government organization
- A website
- A cloud service
- An individual
- Other vulnerable devices
Your infrastructure can become part of someone else's attack.
This gives cybersecurity a second dimension.
You are protecting your business.
But you are also preventing your technology from being used against others.
What Is an Attack Proxy?
Attackers may route malicious activity through compromised infrastructure.
The compromised device acts as an intermediary between the attacker and the target.
This can help obscure the attacker's true location.
To the target, the traffic appears to originate from the compromised system.
This is another reason IP address attribution is complicated.
The source you see may not be the source controlling the activity.
Why Blocking One Malicious IP Address Is Not Enough
This is one of the most important practical lessons from botnets.
Suppose an organization detects repeated attacks from:
IP Address A.
The firewall blocks it.
Excellent.
Five minutes later:
IP Address B
begins the same activity.
Then:
C.
D.
E.
The organization can continue blocking addresses forever.
Or it can ask a better question:
What are these systems trying to reach?
If all of them are attempting the same exposed service, perhaps the root problem is the exposed service.
The better response may involve:
- Restricting access
- Patching the system
- Enabling MFA
- Removing unnecessary exposure
- Rate limiting authentication
- Applying IPS protections
- Changing architecture
Blocking sources is useful.
Reducing opportunity is stronger.
What Is Threat Intelligence?
Threat intelligence provides information about known or suspected malicious activity.
It may include indicators such as:
- IP addresses
- Domains
- URLs
- File hashes
- Malware families
- Behavioral patterns
- Vulnerabilities
- Attack techniques
Organizations can use this information to add context to events.
For example:
Unknown IP attempted to connect
is one piece of information.
Unknown IP attempted to connect and is associated with known malicious scanning activity
provides more context.
But threat intelligence should not be treated as perfect truth.
Can an IP Address Have a Bad Reputation?
Yes.
Security providers maintain reputation systems that evaluate internet infrastructure based on observed activity.
An address may be associated with:
- Spam
- Malware
- Brute force attempts
- Port scanning
- Botnet activity
- Phishing
- Other suspicious behavior
This can help organizations prioritize investigation.
But IP reputation has limitations.
Addresses change ownership.
Cloud infrastructure is shared.
Compromised devices can be cleaned.
Threat information becomes stale.
A reputation score should be treated as:
a signal
not
a verdict.
What Is a False Positive in Threat Intelligence?
A legitimate address can sometimes appear suspicious.
For example:
A cybersecurity researcher may perform large scale scanning.
A cloud provider may host both legitimate and malicious customers.
A previously compromised system may have been cleaned.
An address may have changed owners.
This is why threat intelligence should be combined with:
- Network context
- Authentication information
- Firewall logs
- Endpoint alerts
- Historical behavior
- Business purpose
Cybersecurity improves when multiple signals agree.
How Can I Tell if My Computer Is Part of a Botnet?
There is no single universal symptom.
Potential warning signs could include:
- Unexpected outbound traffic
- Security alerts
- Unknown processes
- Unusual CPU usage
- Unusual bandwidth consumption
- Communications with suspicious infrastructure
- Strange DNS activity
- Unexpected open ports
- Configuration changes
- Endpoint protection detections
But many of these conditions can also have legitimate explanations.
Professional investigation may be necessary.
The absence of symptoms does not prove a device is clean.
Can My Router Be Compromised Without Me Knowing?
Potentially.
A router may continue routing internet traffic while also being compromised.
The same can apply to other infrastructure.
That is why businesses should monitor more than:
“Is the internet working?”
They should also ask:
Is the router current?
Is its configuration expected?
Are there unknown administrators?
Is remote management enabled unnecessarily?
Is it communicating in unexpected ways?
Does the manufacturer still support it?
Availability is not the same thing as security.
How Do I Prevent My Devices From Becoming Part of a Botnet?
There is no single control.
A layered approach is strongest.
1. Change Default Passwords
Do not leave manufacturer defaults in place.
2. Use Unique Credentials
Avoid reusing passwords.
3. Enable MFA
Especially for administrative and remote access.
4. Patch Devices
Keep firmware, software, applications, and operating systems current.
5. Remove Unnecessary Internet Exposure
Do not expose services simply for convenience.
6. Disable Unnecessary Remote Management
Restrict administrative access.
7. Inventory Devices
Know what is connected.
8. Replace Unsupported Equipment
Do not rely indefinitely on technology that no longer receives security fixes.
9. Segment Networks
Separate IoT and other devices where appropriate.
10. Use Endpoint Security
Protect supported computers and servers.
11. Monitor Network Activity
Pay attention to unexpected inbound and outbound behavior.
12. Investigate Alerts
Do not assume security tools will solve everything automatically.
The FTC's current small business guidance reflects many of these same practices, including hardware and software inventory, MFA, patching, changing default manufacturer passwords, limiting network access, separating guest networks, and maintaining an incident response plan.
Why Asset Inventory Is a Botnet Defense
At first this may sound unrelated.
What does inventory have to do with malware?
Everything.
Imagine seeing an unfamiliar device generating unusual traffic.
You ask:
What is this?
Nobody knows.
Who installed it?
Nobody knows.
Who manages it?
Nobody knows.
When was it patched?
Nobody knows.
What is the password?
Nobody knows.
That is a security problem before we even determine whether the device is compromised.
The FTC's current small business guidance, built around NIST CSF 2.0, specifically recommends creating and maintaining an inventory of hardware, software, services, applications, and other technology the business relies upon.
You cannot confidently identify an unauthorized device if you do not know what an authorized environment looks like.
How Network Segmentation Helps
Suppose a security camera becomes compromised.
If the camera network can communicate freely with:
Accounting computers
file servers
employee laptops
point of sale equipment
the compromise may create broader risk.
Now consider a segmented architecture.
The cameras can communicate only with the systems they legitimately require.
A compromise still matters.
But the potential movement is constrained.
This is the principle of containment.
A device should not automatically gain access to everything simply because it is inside the building.
Should IoT Devices Be on a Separate Network?
Often, separating IoT and similar equipment from sensitive business systems can reduce risk.
The exact design depends on the organization.
But asking the question is valuable:
Why does this device need access to that system?
A security camera may need:
- Video recorder access
- Management access
- Time synchronization
- Specific cloud services
It probably does not need unrestricted access to:
- Payroll
- Accounting
- Executive laptops
Segmentation makes those boundaries possible.
Can Antivirus Detect Botnet Malware?
Endpoint security may detect malware associated with botnets.
But no single security technology sees everything.
Some devices cannot run conventional endpoint protection at all.
You may be able to install advanced endpoint protection on a Windows server.
You probably cannot install the same software on every:
- Camera
- Router
- Printer
- IoT sensor
That is why network level visibility is also important.
Why Network Monitoring Matters for IoT Security
Many IoT devices have limited local security visibility.
Network behavior can provide useful clues.
Ask:
Is the device online?
What does it communicate with?
Did that behavior change?
Is it transferring unexpected data?
Did it begin contacting new destinations?
Is it generating unusual traffic?
Again, no single behavior automatically proves compromise.
But monitoring provides evidence for investigation.
What Happens if My Business Is Participating in a DDoS Attack Without Knowing It?
That should be treated as a potential security incident.
A device generating malicious traffic may indicate compromise.
The organization may need to:
- Identify the source
- Isolate affected systems
- Review logs
- Scan for malware
- Update software
- Reset compromised credentials
- Determine how access occurred
- Verify whether additional systems are affected
- Follow appropriate incident response procedures
Do not simply block outbound traffic and assume the underlying problem is solved.
The malicious communication may be the symptom.
The compromise is the root problem.
What Should I Do if I Suspect a Device Is Part of a Botnet?
The appropriate response depends on the device and circumstances.
A general incident response process may involve:
Identify
Determine which device is generating suspicious activity.
Contain
Limit the device's ability to communicate where appropriate.
Preserve Information
Retain relevant logs and evidence.
Investigate
Determine what occurred and how.
Remediate
Remove malware, fix vulnerabilities, reset credentials, update software, or replace equipment.
Verify
Confirm that malicious activity has stopped.
Review
Determine whether similar devices may have the same weakness.
That last step is critical.
If one camera was compromised because all cameras use the same default password, cleaning one camera does not solve the organizational problem.
One Compromised Device Should Trigger a Bigger Question
Suppose one router is compromised.
Do not only ask:
“How do we fix this router?”
Ask:
“Do our other routers have the same configuration?”
If one camera uses default credentials:
Do all cameras use them?
If one server missed a patch:
Did other servers miss it too?
If one vendor account was forgotten:
Are there others?
A security incident should improve the entire environment.
Botnets Demonstrate Why Cybersecurity Is a Scale Problem
Attackers use automation because manual activity does not scale.
Businesses should think the same way about defense.
Imagine an organization with:
50 locations
500 network devices
1,000 users
Manual inspection alone cannot provide continuous awareness.
Defenders need technology that can help:
- Inventory
- Monitor
- Detect
- Correlate
- Alert
- Prioritize
Then people can investigate what matters.
This is the same principle we have seen throughout this series:
> Attackers automate scale. Defenders need to automate awareness.
Where USA Telecom and ADAM Fit
Botnets reinforce why network visibility matters.
USA Telecom and ADAM are not a replacement for:
- Endpoint detection and response
- Antivirus
- SIEM platforms
- Firewalls
- Threat intelligence systems
- Identity security
- Vulnerability management
Those technologies provide specialized security capabilities.
But an organization also needs operational awareness across its infrastructure.
ADAM can support the broader process of understanding:
What is connected?
What is reachable?
What changed?
What stopped responding?
What location is affected?
What network path is involved?
Does the activity require investigation?
That visibility helps shorten the gap between:
Something happened
and
Someone noticed.
Monitoring Is Especially Important in Distributed Businesses
Consider a company operating 100 locations.
Each location may contain:
- Firewall
- Router
- Switches
- Wireless access points
- Cameras
- Phones
- Printers
- IoT devices
- Vendor equipment
That can quickly become thousands of devices.
A business should be able to answer:
Which devices are supposed to exist?
Which are online?
Which are unsupported?
Which locations changed?
Which equipment is behaving unexpectedly?
Who owns each device?
Without centralized visibility, configuration inconsistencies become easier to miss.
Attackers benefit from inconsistency.
Standardization helps defenders.
Botnets Also Demonstrate Why Root Cause Matters
Suppose your firewall receives attacks from 5,000 different IP addresses.
One response would be:
Block 5,000 IP addresses.
But why are they all attempting the same service?
Maybe:
The service is unnecessarily exposed.
The software is outdated.
A login interface should be restricted.
MFA is missing.
The firewall rule is too broad.
The attack traffic is the symptom.
The exposure may be the root cause.
This is where security becomes architecture rather than whack a mole.
20 Questions Every Business Should Ask About Connected Devices
1. Do we know every device connected to our network?
2. Who owns each device?
3. Who manages it?
4. Were the default credentials changed?
5. Is the firmware current?
6. Is the manufacturer still supporting it?
7. Does the device require internet access?
8. Does it require inbound internet access?
9. Is remote administration enabled?
10. Does remote administration actually need to be enabled?
11. Can MFA be enabled?
12. Is the device on the appropriate network segment?
13. What other systems can it communicate with?
14. Are IoT devices separated from sensitive business systems?
15. Can we identify unusual outbound communication?
16. Would we know if the device stopped responding?
17. Are security and availability logs retained?
18. What happens when a device reaches end of support?
19. What is our process for removing old equipment?
20. Who investigates when something behaves unexpectedly?
Those questions turn IoT and network security from:
“Is the device working?”
into:
“Is the device known, supported, secured, and behaving as expected?”
The Better Question Is Not “Who Is Attacking Us?”
When an organization sees suspicious traffic, the natural question is:
“Who is this?”
That can be useful.
But botnets demonstrate why attribution can be complicated.
The IP address may belong to another victim.
The attacking device may be compromised.
The person directing the attack may be somewhere entirely different.
So ask additional questions:
What are they trying to reach?
Why is it reachable?
Was anything successful?
What vulnerability are they testing?
Can we reduce the exposure?
Are similar systems affected?
Are we monitoring the right things?
The identity of the attacker matters.
But reducing the opportunity often matters more.
Key Takeaway
A botnet changes the scale of cybercrime.
An attacker does not necessarily need:
one powerful computer.
They can potentially control:
thousands of ordinary computers and devices.
Those devices may belong to:
businesses
families
schools
government organizations
cloud customers
people who have no idea they are participating in an attack.
That is why cyberattacks can appear to come from everywhere.
And it is why simply blocking one malicious address is rarely enough.
Businesses should focus on the fundamentals:
Know what is connected.
Change default credentials.
Patch devices.
Replace unsupported equipment.
Reduce unnecessary exposure.
Segment networks.
Protect administrative access.
Monitor inbound activity.
Monitor outbound activity.
Investigate anomalies.
And remember:
> The computer attacking you may itself be a victim.
The important question is not only:
“Who should we block?”
It is:
“What are they trying to exploit, and why do they have the opportunity to try?”
Frequently asked questions
What is a botnet?
A botnet is a network of compromised computers or devices that can be remotely controlled and coordinated by an attacker. NIST describes botnets as networks of infected machines that criminals can remotely manage.
What does botnet mean?
The term combines “bot,” meaning an automated or remotely controlled system, with “network.”
How does a botnet work?
Attackers compromise multiple devices and establish a mechanism for remotely instructing them. The devices can then perform coordinated activities such as scanning, sending spam, attempting credentials, spreading malware, or participating in DDoS attacks.
What devices can become part of a botnet?
Computers, servers, routers, cameras, IoT equipment, network devices, and other internet connected systems can potentially become compromised.
Can a security camera become part of a botnet?
Potentially, yes. Connected cameras are computers running software and may become vulnerable if they use weak credentials, outdated firmware, unnecessary internet exposure, or exploitable software.
Can a router become part of a botnet?
Yes. Routers run software and can become targets if they are poorly configured, use weak credentials, expose unnecessary management services, or contain exploitable vulnerabilities.
Can a server become part of a botnet?
Yes. Compromised servers may provide attackers with processing power, bandwidth, storage, and continuous internet connectivity.
What do botnets do?
Botnets may be used for DDoS attacks, scanning, password attacks, spam, malware distribution, fraud, proxy services, and other malicious activities.
What is a DDoS attack?
A distributed denial of service attack uses traffic from many systems to overwhelm a network, website, application, or service so legitimate users cannot access it.
Why do botnet attacks come from many IP addresses?
Because the attack can be distributed across large numbers of compromised devices located on different networks and in different countries.
Is the IP address attacking me the hacker's IP address?
Not necessarily. The source may be a compromised device, proxy, cloud server, or other intermediary being used by the attacker.
Should I block malicious IP addresses?
Blocking known malicious sources can be useful, but it is not a complete defense against botnets because attackers may use many different addresses. Organizations should also reduce exposure, patch vulnerabilities, use MFA, and investigate the underlying target.
How do botnets spread?
Some botnets can search for and exploit additional vulnerable devices, allowing the malicious network to grow automatically.
Do botnets use default passwords?
Weak or default credentials can be one method attackers use to compromise devices.
What is botnet command and control?
Command and control refers to the infrastructure or mechanisms attackers use to communicate with compromised devices and issue instructions.
How do I know if my computer is part of a botnet?
Possible indicators include malware detections, unusual outbound traffic, unexplained network activity, unexpected processor use, or communications with malicious infrastructure. Professional investigation may be needed because these indicators can also have legitimate causes.
How do I know if my router is compromised?
Signs may include unexplained configuration changes, unexpected accounts, unusual network communications, security alerts, or other anomalous behavior. The router should also be checked for current firmware, supported lifecycle status, secure administration, and expected configuration.
Can antivirus remove botnet malware?
Endpoint security may detect and remove some botnet malware, but no single product detects every threat, and many IoT or network devices cannot run traditional antivirus.
How can I prevent my devices from becoming bots?
Change default credentials, use MFA where supported, patch devices, remove unnecessary internet exposure, disable unnecessary remote management, segment networks, inventory equipment, replace unsupported hardware, and monitor for unusual behavior.
Are botnets only a problem for large companies?
No. Automated attacks can discover vulnerable equipment regardless of the size of the organization operating it.
Can my business accidentally attack another company?
If one of your systems becomes compromised and is incorporated into malicious infrastructure, attackers may potentially use it to generate traffic or attacks against other systems.
What should I do if a device is participating in a botnet?
Treat it as a possible security incident. Identify and contain the device, preserve relevant information, investigate the compromise, remove malicious software or replace the equipment, patch vulnerabilities, reset affected credentials, and determine whether similar devices are exposed.
Sources
- CISA — Cyber Hygiene Services. Free vulnerability and web application scanning for enrolled organizations.
- CISA — Known Exploited Vulnerabilities (KEV) Catalog. Only vulnerabilities with reliable evidence of active exploitation in the wild.
- CISA — Internet Exposure Reduction Guidance. Evaluating necessity of exposure, and removing or restricting access to assets that do not need to be internet accessible.
- FTC — How To Secure Your Home Wi-Fi Network. “Change the default administrative username, password, and network name to something unique.”
- FTC — How To Secure Your Home Security Cameras. Do not use the camera’s default username and password, and do not reuse a password from another account.
- NIST — The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29, 26 February 2024).
- FTC — Cybersecurity for Small Business.
Cybersecurity risk and the controls appropriate to it vary by organization. Evaluate these recommendations against your own technology environment, business requirements, regulatory obligations, threat profile and risk tolerance.
USA Telecom Consulting LLC is a Service-Disabled Veteran-Owned Small Business running a 24/7 NOC. We monitor networks, circuits and firewalls for regulated and defense-supply-chain organizations.
How do I know if someone is hacking my network? · Why would hackers target my small business? · How do hackers find vulnerable computers? · Does a firewall stop hackers? · Is Remote Desktop or SSH safe to expose to the internet? · What happens after a hacker gets into your server? · What is malware, and how do you know if a file is malicious? · Latency vs jitter vs packet loss