BotNet News

Your source for Online Security News

A botnet is a network of compromised computers and devices (or “bots”) under the control of a cybercriminal, or “bot herder.” Botnets are used to perform various malicious tasks such as sending spam emails, infecting other devices with malware, stealing sensitive information from infected computers, or launching DDoS attacks that can disrupt major internet services.

Cybercriminals typically set up botnets through phishing attacks, software vulnerabilities, or by exploiting default credentials on routers and other IoT gadgets. They then use remote access to the devices to install malware, and if successful, the device becomes part of the botnet and can be controlled remotely.

Bots are usually installed on insecure PCs, but they can also be deployed on IoT devices such as routers and home security cameras. IoT devices are a favorite target for bot attacks because they’re often sold with insecure default passwords or shipped with vulnerable software.

Once the bots are installed on infected devices, they can be commanded to perform various malicious tasks by their herders via communication channels like Internet Relay Chat networks and website and domain domains. Bot herders can also instruct bots to launch DDoS attacks by flooding the victim server or network with excessive traffic that overwhelms its capacity and prevents legitimate users from accessing it.

Historically, bots were controlled through a client-server model in which the bots would contact a centralized command and control (C&C) server to receive instructions from the bot herder and report their results back. However, due to aggressive action by law enforcement and cybersecurity agencies in shutting down centralized C&C servers around the world, many bot herders now prefer decentralized peer-to-peer control models.