Back to glossary

Botnet

3 min read

A botnet is a network of computing devices that have been compromised and are controlled remotely by a single operator.

July 30, 2026
Compartir:

A botnet is a network of computing devices that have been compromised and are controlled remotely by a single operator.

Those devices, usually called bots or zombies, can be desktop machines, servers, IoT devices and mobile phones that have been infected with malware written to enrol them into the network.

What makes a botnet a botnet is the operator’s ability to command many devices at the same time and point their combined capacity wherever they want.

How one gets built

Silent infection. Devices normally join without their owner noticing anything. The malware arrives by email, from a malicious site, or through a vulnerability in a system or an application that was never patched.

Remote control. Once a device has joined, the operator can send it instructions, pull information from it and coordinate it with the rest. That channel is command and control, and it is what turns a pile of infected machines into a usable network.

Pooled capacity. A botnet does things a single machine cannot, because it adds up the bandwidth, the addresses and the processing time of thousands of hosts.

Persistence. Botnets are built to survive. Operators update the malware, change how it spreads, and rebuild the network after part of it is taken down.

What they are used for

Distributed denial of service. The best known use: thousands of coordinated devices flood a service with traffic until it stops answering real users. That is what DDoS describes.

Spam and phishing at volume. Mail sent from thousands of residential addresses is harder to filter than mail sent from one server.

Stealing information. Control of a device means access to what is stored on it and to what is typed into it: credentials, banking details, personal data.

Mining cryptocurrency. Someone else’s electricity and someone else’s processor, which is what cryptojacking means in practice.

Advertising fraud. Automated clicks and impressions billed as if a person had made them.

A worked example

An operator holds a botnet of several thousand compromised hosts: home computers, small business servers, and IoT devices such as cameras and routers.

At a chosen moment the order goes out, and every device starts making requests against the same target at once.

The target’s network sees a volume of traffic it was never sized for. Its online services stop answering real customers, and from the outside the incident looks like an outage rather than an attack.

Two things make it hard to answer. The traffic arrives from thousands of legitimate addresses belonging to people who have done nothing wrong, so blocking by address is a blunt instrument; and the owners of those devices have no idea that their camera is taking part.

Where this shows up in an audit

Botnets are the reason two defences that get treated as optional are not. Patching what is exposed to the internet matters because that is how devices are recruited in the first place. Knowing what leaves your network matters because a device that has joined a botnet has to reach its controller to be worth anything, and that outbound connection is usually the first observable sign that a host is no longer yours.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.