BotNet News

Your source for Online Security News

A botnet is a network of Internet-connected computers, devices and other systems infected with malware and used to carry out malicious activities. Attackers, also known as bot herders, use botnets to carry out distributed denial-of-service attacks (DDoS), steal credentials from online accounts, harvest CPU-intensive tasks, and more.

Bot malware is typically spread through file sharing, email attachments, social media application protocols, and other means. Once a device is infected, it reports back to its attacker, or bot-herder. The bot-herder then dictates commands to the infected system. Depending on the threat actor’s purpose, a bot can change its functionality, and some can even take over web browsers to intercept HTTP/2 traffic, as was the case with the 911 S5 botnet that took down services in the aftermath of the 2017 Equifax breach.

Traditionally, centralized bot networks operate with one command-and-control server. The server is referred to as the C&C and is used to communicate with infected bots, which remain dormant until told to activate by their attackers. The bots then report back to the C&C using a variety of communication channels including Internet Relay Chat, and protocols commonly enabled on work and home firewalls that don’t block these messages.

More recent botnets use a peer-to-peer (P2P) model where every infected device acts as both a client and server to each other. This makes them harder for law enforcement and security vendors to pinpoint, and obfuscates communication between the infected system and the attacker.