Botnets - How Infected Device Networks Operate
About 2 min read
A botnet is a network of numerous computers and devices infected with malware that are remotely controlled by an attacker. Infected devices are called "bots" or "zombies" and, without their owners noticing, are used for malicious activities such as DDoS attacks, sending spam email, and credential stuffing. The 2016 Mirai botnet commanded roughly 600,000 IoT devices and caused large-scale internet outages. In 2024, Mirai variants remain highly active, and attacks targeting IoT devices are on the rise.
The Structure of a Botnet
Botnets are controlled either in a centralized way, built around a C&C (Command and Control) server, or in a P2P way, where the infected hosts relay commands among themselves. A centralized botnet can be neutralized by cutting off the C&C server, whereas in a P2P botnet the nodes communicate directly with one another, so there is no single point of failure and takedown is difficult. As IoT devices have proliferated, the number of cases in which routers, cameras, and other devices with weak security are incorporated into botnets has surged.
Clues That Reveal an Infected Device
A device that has been recruited into a botnet keeps connecting to its C&C server to receive commands, so traces remain in the communication records. When several devices on an internal network contact the same destination at regular intervals, it suggests a program is running independently of anything the users are doing. The shared destination and the periodicity of the traffic are the clues that narrow down which devices are infected. Once such a device is identified, it is disconnected from the network and cleaned up, in order to cut off incoming commands and stop the infection from spreading to other machines.
Diagram: Centralized and P2P Structures
A Common Misconception
A common misconception is that "even if my device is incorporated into a botnet, there is no real harm." In reality, the device's processing power and network bandwidth are consumed, which not only slows it down but can also expose you to legal risk by serving as a stepping stone for criminal activity. For example, when a home router is left with its default password, cases have been confirmed in which it is incorporated into a botnet within a few hours.
How to Prevent Infection
It is important to keep your device firmware up to date and to always change the default password. Set a strong, random password on your router and IoT devices to prevent them from being incorporated into a botnet. A suspicious increase in traffic or a slowdown in device performance may be a sign of infection.
Was this article helpful?