What Is a Botnet in Cyber Security? How Botnets Are Built and Stopped
A botnet is a network of internet-connected devices infected with malware and controlled remotely by an attacker, used to launch large-scale attacks like DDoS campaigns, spam distribution and credential stuffing without the device owners’ knowledge. If you have ever wondered whether your own device could be part of one without you knowing, this guide covers exactly how to check.
What Is a Botnet?
A botnet is a network of compromised, internet-connected devices, computers, servers, IoT devices, working together under an attacker’s remote control, without their owners’ knowledge or consent. The word itself blends “robot” and “network,” reflecting how each infected device acts as a small, obedient piece of a much larger criminal operation.
Attackers use botnets to carry out attacks at a scale a single device could never achieve alone, borrowing the combined bandwidth and processing power of potentially millions of infected machines simultaneously.
Bot vs. Botnet vs. Zombie Computer: What’s the Difference?
A bot is a single piece of software running on an infected device, executing commands from its controller. A zombie computer is the infected device itself, the physical machine now under an attacker’s remote control without its owner’s awareness. A botnet is the entire network, potentially thousands or millions of these zombie computers, all bots, working together under one attacker’s coordination.
Think of it as a hierarchy: individual bots run on individual zombie computers, and the botnet is the collective term for the whole compromised army together.
How Are Botnets Built?
Botnet construction starts with infection, spreading malware through phishing emails, malicious downloads, exploited software vulnerabilities, or, increasingly, weak default credentials on internet-connected IoT devices like routers and security cameras.
Once infected, each device establishes contact with command and control infrastructure, the botmaster’s central system issuing instructions. Two structural models dominate. The client-server model uses a centralized command and control server all bots report to directly, simpler to build but easier for defenders to disrupt by targeting that single point. The peer-to-peer model has infected devices communicate with each other directly, distributing control across the network itself, considerably harder to take down since there is no single server to seize.
The bot herder, also called the botmaster, is the individual or group operating the botnet, issuing commands and, in many cases, renting access to the botnet’s combined power out to other criminals for a fee.
What Do Botnets Do?
Botnets carry out several distinct attack types, each exploiting the botnet’s combined scale differently. DDoS attacks flood a target server or network with overwhelming traffic from thousands of devices simultaneously, knocking legitimate services offline. Spam distribution uses infected devices to send massive volumes of phishing or spam email, since traffic originating from many different addresses is harder to block than a single source.
Credential stuffing uses a botnet to rapidly test stolen username and password combinations against login pages at scale, automating what would otherwise be an impossibly slow manual process. Click fraud generates fake ad clicks across infected devices to drain a competitor’s advertising budget or generate fraudulent ad revenue. Crypto mining silently uses an infected device’s processing power to mine cryptocurrency for the botmaster, often without the device owner ever noticing beyond degraded performance.
Real-World Botnet Examples (Mirai, Qakbot’s “Operation Duck Hunt,” 911 S5)
Mirai, discovered in 2016, specifically targeted vulnerable IoT devices, routers, cameras, DVRs, using default factory credentials nobody had bothered to change. At its peak, it powered some of the largest DDoS attacks recorded at the time, disrupting major internet infrastructure and demonstrating just how dangerous poorly secured consumer devices could become at scale.
Qakbot, a long-running banking trojan turned botnet, provided initial network access other criminals bought to deploy ransomware, facilitating dozens of attacks generating tens of millions in ransom payments. The FBI’s Operation Duck Hunt, announced August 29, 2023, dismantled it through an unusually direct technical approach: agents gained access to Qakbot’s own administrative infrastructure, identified more than 700,000 infected computers worldwide, then redirected the botnet’s own traffic through FBI-controlled servers to push an uninstaller directly to every infected machine. The operation, conducted with partners across France, Germany, the Netherlands, Romania, Latvia and the UK, also seized $8.6 million in cryptocurrency for return to victims.
911 S5, described by FBI Director Christopher Wray as likely the largest botnet ever built, infected more than 19 million IP addresses across nearly 200 countries by 2022. Rather than a typical infection method, it spread through free VPN applications that secretly turned users’ own computers into paid proxy relays for cybercriminals. Its administrator, arrested in Singapore in May 2024, had generated roughly $99 million selling access to those hijacked IP addresses, which criminals then used for everything from cyberattacks to an estimated $5.9 billion in fraudulent pandemic relief applications routed through the botnet’s disguised, residential-looking connections.
How Do I Know If My Device Is Part of a Botnet?
Most botnet infections are deliberately designed to stay invisible, since a botmaster benefits from an infected device continuing to run undetected for as long as possible. Still, several concrete signs are worth checking directly rather than assuming everything is fine simply because nothing looks obviously broken.
Unusually slow performance or a fan running constantly at high speed, even when you are not actively using the device for anything demanding, can indicate background processes consuming resources without your knowledge. Check your router’s connected devices list and outgoing traffic if your provider offers that visibility, since unexplained network activity, particularly at unusual hours when the device should be idle, is a genuine warning sign worth investigating.
For IoT devices specifically, check whether the default administrator password was ever actually changed, since Mirai and similar botnets specifically scan for devices still running factory credentials. Unexpected reboots, unfamiliar processes in your task manager or activity monitor, and a device that seems to run hot or drain battery unusually fast on mobile hardware are all worth investigating rather than dismissing.
If you suspect infection, running a reputable malware scan is the appropriate first step, followed by changing all passwords from a separate, known-clean device if the scan confirms a genuine infection, since credentials entered on a compromised device may already be captured. For IoT devices specifically, a factory reset followed by immediately setting a strong, unique password before reconnecting to your network closes the exact gap botnets like Mirai were built to exploit.
How Are Botnets Stopped? Technical Disruption vs. Law Enforcement Takedowns
Two genuinely different mechanisms disable botnets, and understanding the distinction explains why some takedowns last while others see the same botnet resurface under a new name months later.
Technical disruption involves security researchers or infrastructure providers identifying and blocking command and control communication, often through sinkholing, redirecting a botnet’s traffic away from its criminal controllers toward a server researchers control instead. This can happen relatively quickly once C&C infrastructure is identified, but it does not remove the underlying malware from infected devices, and a technically skilled botmaster with backup infrastructure can sometimes rebuild and resume operations.
Law enforcement takedowns go considerably further, combining technical disruption with legal authority to seize physical servers, freeze cryptocurrency assets, and, when jurisdiction allows, arrest the individuals actually operating the botnet. Operation Duck Hunt against Qakbot exemplifies this combined approach precisely: FBI agents did not just block communication, they gained lawful access to the botnet’s own infrastructure and used it to push a legitimate uninstaller directly to every infected victim machine, genuinely removing the malware rather than merely cutting off its communication. The 911 S5 takedown went further still, resulting in the arrest of the botnet’s administrator alongside infrastructure seizure, directly disrupting the human operation behind the network rather than only its technical footprint.
The honest limitation worth naming directly: even a successful, thorough takedown does not guarantee permanence. 911 S5 itself was briefly disrupted once in 2022 before resurfacing under a new name months later, and Qakbot’s own operators, while stripped of infrastructure, faced no arrests in that specific operation, leaving open the possibility of rebuilding elsewhere. Technical disruption alone is often temporary. Law enforcement action targeting the people behind a botnet, not just its infrastructure, tends to cause more lasting damage to the criminal operation itself.
How to Protect Your Business and IoT Devices From Botnets
Change every default password on every internet-connected device immediately after purchase, since this single action closes the exact gap botnets like Mirai were specifically built to exploit at scale. Keep firmware and software updated on all devices, particularly routers and IoT hardware often neglected long after initial setup.
Segment IoT devices onto their own separate network, isolated from your primary business systems, so a compromised smart device cannot serve as a stepping stone into more sensitive infrastructure. Deploy endpoint monitoring capable of flagging unusual outbound traffic patterns, since botnet communication often looks different from normal device behavior once you know what to watch for. For businesses specifically, monitor for credential stuffing attempts against your own login systems, since botnets frequently target exactly this kind of automated, large-scale authentication abuse.
Is Running a Botnet Illegal? US and UK Regulatory Tools Compared
Operating a botnet is unambiguously illegal in both the US and UK, though the specific legal tools each country uses differ somewhat. In the US, the Computer Fraud and Abuse Act provides the primary federal statute prosecutors use against botnet operators, covering unauthorized access to computers and the resulting damage, alongside wire fraud and money laundering charges typically layered on top when financial gain is involved, exactly the combination used against 911 S5’s administrator.
In the UK, the Computer Misuse Act serves the equivalent function, criminalizing unauthorized access to computer systems and the intent to impair their operation. The UK also participates directly in international botnet takedown operations through partnerships coordinated via the Five Eyes intelligence alliance, and the NCSC’s own Code of Practice for Consumer IoT Security specifically addresses the default-credential weakness botnets like Mirai historically exploited, requiring manufacturers to eliminate universal default passwords on new consumer devices sold in the UK.
Both countries increasingly coordinate directly on cross-border takedowns, since botnet infrastructure and operators rarely sit neatly within one jurisdiction alone. Qakbot’s takedown alone involved law enforcement across six countries beyond the US, reflecting how genuinely international this enforcement work has become. Cyber Security Solutions Ltd tracks these coordinated international operations closely, since a botnet takedown announced in one country often has direct, immediate relevance for businesses on the other side of the Atlantic too.
Conclusion
Botnets remain one of the more quietly persistent threats in cyber security precisely because infected devices are built to stay invisible for as long as possible. Start by checking your own network for the warning signs covered above, and make sure every connected device, especially IoT hardware, has moved past its factory default password. To get your business’s network assessed for signs of botnet compromise, visit cybersecuritysolutionsltd.com for expert support from Cyber Security Solutions Ltd.
FAQs
A botnet is a network of infected devices, computers, servers, IoT devices, controlled remotely by an attacker without their owners’ knowledge, used together to launch large-scale attacks like DDoS campaigns, spam distribution and credential stuffing at a scale a single device could never achieve alone.
A bot is the software running on an infected device. A zombie computer is that infected device itself, under remote attacker control. A botnet is the entire collective network of many zombie computers and their bots, working together under one attacker’s coordination.
Watch for unusually slow performance, constant high fan activity when idle, unexplained network traffic, and unfamiliar background processes. For IoT devices, check whether default passwords were ever changed. Running a reputable malware scan is the appropriate first step if you suspect infection.
The 911 S5 botnet, dismantled in May 2024, is described by the FBI as likely the largest ever built, infecting more than 19 million IP addresses across nearly 200 countries through malicious free VPN applications before its administrator’s arrest in Singapore.
Through two mechanisms: technical disruption, blocking or redirecting command and control communication, and law enforcement takedowns, which combine technical disruption with server seizures, asset freezes and arrests. Takedowns targeting the people behind a botnet tend to cause more lasting disruption than technical measures alone.
Yes, unambiguously, in both the US and UK. US prosecutors typically use the Computer Fraud and Abuse Act alongside wire fraud and money laundering charges. The UK uses the Computer Misuse Act. Both countries increasingly coordinate directly on cross-border botnet takedowns together.
