Attack technique

Botnet

A network of compromised devices controlled remotely by an attacker and used to carry out attacks at scale.

Definition

A botnet is a collection of internet-connected devices infected with malware and controlled remotely by an attacker, who can direct all of them to act together without their owners knowing.

The devices in a botnet are ordinary: home routers, security cameras, servers, laptops and increasingly Android phones. What makes them a botnet is a control channel that lets one operator issue instructions to all of them at once.

Botnets are rented as infrastructure. An operator builds and maintains the network, then sells access, which means the person who infected a device is often not the person who attacks with it. This separation is why removing malware from one device does nothing to disrupt the wider network.

What a botnet is used for varies: overwhelming a target with traffic in a DDoS attack, sending spam and phishing at volume, distributing malicious files, brute-forcing credentials, or mining cryptocurrency using the victim's electricity.

At a glance

Severity
High
Prevalence
Widespread, and growing with poorly secured connected devices
Primary targets
Home routers, IoT devices, unpatched servers, Android phones

How it works

  1. 1

    Infection: a device is compromised through malware, a known vulnerability, or default credentials that were never changed

  2. 2

    Enrolment: the malware contacts a command-and-control channel and registers the device as available

  3. 3

    Persistence: it survives reboots and often hides from casual inspection

  4. 4

    Tasking: the operator issues instructions to some or all devices at once

  5. 5

    Monetisation: capacity is used directly or rented out to other attackers

Warning signs

  • A device running hot, slow, or using bandwidth when nobody is using it
  • Outbound connections to unfamiliar addresses, especially on unusual ports
  • Your IP address appearing on a spam or abuse blocklist
  • Connected devices still using their factory default credentials
  • An Android phone that became slow or hot shortly after installing a file received in a message

How to defend

  • Change default credentials on every connected device, especially routers and cameras
  • Patch firmware on network equipment, which is the most commonly neglected category
  • Segment IoT devices away from systems that hold sensitive data
  • Monitor outbound traffic, since botnet activity is visible on the way out even when infection was silent
  • Train staff not to install applications from messages, which is the main recruitment route for mobile devices

Real-world example

An Indonesian company discovers its office IP address is blocked by several email providers. The cause is a networked security camera, installed years earlier with its factory password unchanged, that had been recruited into a botnet and was sending spam continuously. No employee did anything wrong, and no laptop was infected.

How Claro helps

Botnets are how phishing achieves scale, and in Indonesia the malicious APK campaigns spread through WhatsApp recruit phones into exactly this kind of network. Claro measures whether staff would install such a file in the first place, which is the recruitment step a botnet depends on.

Frequently asked questions

What is a botnet?

A botnet is a network of internet-connected devices infected with malware and controlled remotely by a single operator, who can direct all of them to act together without the owners knowing.

What is a botnet used for?

Common uses are DDoS attacks, sending spam and phishing at volume, distributing malware, brute-forcing credentials, and cryptocurrency mining using the victim's electricity. Access is frequently rented to other attackers.

How do I know if my device is part of a botnet?

Look for a device that runs hot or slow, uses bandwidth when idle, makes outbound connections to unfamiliar addresses, or an IP address that has appeared on a spam blocklist. Mobile devices often become noticeably slow or hot after a malicious install.

Can a phone be part of a botnet?

Yes. Android devices are actively recruited, commonly through malicious install files sent over messaging apps. This is why installing an application to view a document is such a consequential action.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo