BotNet News

Your source for Online Security News

Cybercriminals build botnets to leverage the collective computing power and functionality of thousands or even millions of devices (or zombie computers) for a wide variety of attacks on users and businesses. Typical attacks include stealing user data, causing website and service outages, spreading malware, and generating malicious traffic for distributed denial-of-service (DDoS) attacks.

Attackers that create and operate a botnet typically use malware to infect a large number of targets. These targets can be traditional desktop and laptop computers running Windows OS or macOS, IoT devices such as routers, smart home devices and cameras, or mobile phones running Android or iOS. Infections can be accomplished through security flaws, phishing emails, and malware downloaded from compromised websites or file hosts. Once a significant number of target machines are infected, the attacker (or bot herder) uses a C&C server to remotely manage the entire network of infected devices, or bots.

In many botnets, the attacker uses a centralized client-server model in which a command and control (C&C) server sends automated commands to infected bots via a communications protocol such as Internet Relay Chat. The bots are often programmed to remain dormant and wait for instructions from the C&C server before engaging in a cyberattack.

Other botnets, however, are decentralized through a peer-to-peer (P2P) network approach in which each infected device serves as both a C&C server and a client that receives instructions. This model can be difficult for law enforcement and security agencies to track down, and it makes it more challenging to shut down the botnet’s central servers.