Skip to content
Thursday, September 10, 2026
Cubed News Daily News, Reframed · cubednews.com · also cubednews com / CubedNews
Issue №102
Thursday, September 10, 2026 · Global Edition
Subscribe
Independent· Source-cited· Premium editorial standard· 8-editor team· cubednews.com
Latest What a Botnet Is, and How It Powers Cyberattacks
Technology TECHNOLOGY

What a Botnet Is, and How It Powers Cyberattacks

A botnet is a network of secretly infected devices under an attacker's remote control, used together to launch large-scale cyberattacks.

𝕏 in f

A botnet is a network of internet-connected devices that have been secretly infected with malicious software and are controlled remotely by an attacker, who directs them all at once to carry out large-scale attacks. Each infected device is called a bot, and the person or group commanding them is often called a bot herder or botmaster. The power of a botnet comes from numbers: thousands or millions of ordinary machines, acting together on command.

Because the owners of infected devices usually have no idea their machines have been recruited, botnets are one of the most persistent tools in cybercrime. Understanding how devices are enlisted, how they take orders, and what they are used for shows why they are so hard to shut down.

What is a botnet made of?

A botnet is made of many compromised devices working together under one attacker’s control. A single infected device is a bot; the coordinated collection of them is the botnet. What ties them together is command software that lets the attacker issue instructions to all of them simultaneously.

Crucially, a botnet is not limited to computers. Any internet-connected device can be recruited, including home routers, security cameras, and other smart gadgets, which are often poorly secured and rarely updated. This is why the rise of connected devices has expanded the raw material available to bot herders.

How does a device become part of a botnet?

A device becomes part of a botnet when an attacker exploits a security vulnerability or a weakness such as a default password to install malicious software on it. The infection is designed to be quiet, so the device keeps working normally while secretly awaiting orders.

Common entry routes include phishing emails, malicious downloads, and automated scanning that hunts the internet for devices with known flaws or unchanged factory passwords. Once installed, the malware connects the device back to the attacker’s infrastructure and adds it to the pool of machines ready to act. The victim typically notices nothing beyond, perhaps, a device running warm or a little slower than usual.

How does a botnet take orders?

A botnet takes orders through a command-and-control system, often shortened to C2 or C&C, which is the channel the attacker uses to send instructions and collect stolen data. There are two main designs for this control structure, and they trade off simplicity against resilience.

Control model How it works Main weakness
Client-server (centralized) A central command server sends instructions to every bot, which relies solely on that server If the server is found and shut down, the whole botnet is disabled
Peer-to-peer (decentralized) Any bot can pass instructions to others, with no single control point Harder to disrupt, but more complex for the attacker to coordinate

The client-server model is simpler but has a single point of failure, which defenders can target. The peer-to-peer model emerged precisely to avoid that vulnerability, spreading control across the network so there is no one server to disable. This resilience is a major reason large botnets can survive attempts to take them down.

What attacks do botnets power?

Botnets power a range of attacks, but the most notorious is the distributed denial-of-service, or DDoS, attack. In a DDoS, the attacker commands the whole botnet to flood a target website or service with traffic at the same time, exhausting its bandwidth or computing resources so legitimate users can no longer reach it.

Because the flood comes from many different devices at once, it is far harder to block than an attack from a single source, which is what the distributed in DDoS refers to. Beyond DDoS, botnets are used to send spam and phishing at scale, harvest passwords and financial data, and spread further malware. They are also rented out through so-called attack-for-hire services, letting even unskilled criminals launch powerful attacks for a fee.

How can you tell if a device is infected, and reduce the risk?

You often cannot tell easily, because botnet malware is built to stay hidden, but warning signs include unexplained slowdowns, a device running hot, unusual network activity, or crashes. On networks, unexpected spikes in outbound traffic can hint that a device is being used in an attack.

Reducing the risk relies on basic security hygiene. Changing default passwords on routers and smart devices, keeping software and firmware updated, being wary of unexpected attachments and downloads, and using reputable security tools all close the doors that bot herders rely on. Because many botnets exploit neglected internet-of-things devices, keeping those updated matters as much as protecting a main computer.

Why are botnets so hard to shut down?

Botnets are hard to shut down because they are distributed by design, spread across countless devices in many places and often owned by people who have no idea they are involved. There is rarely a single machine to seize; disabling one bot barely dents a network of thousands or millions.

Decentralized peer-to-peer control makes this worse, because there is no central server for defenders to target and take offline. Even when a command server is found and shut down, a resilient botnet can re-establish control through backup channels. The devices themselves are often cheap, rarely patched gadgets whose owners may never notice or fix the infection, giving the botnet a long and quiet life.

Why has the internet of things expanded the threat?

The internet of things has expanded the botnet threat by adding billions of connected devices that are frequently insecure and seldom maintained. Smart cameras, routers, printers, and home gadgets often ship with weak or default passwords and infrequent updates, making them easy for automated scanning tools to find and hijack.

These devices are attractive recruits because they are always on, connected to the internet, and rarely watched. A compromised smart camera can sit in a botnet for months, contributing to attacks while its owner notices nothing. As the number of connected devices grows, so does the pool of potential bots, which is why securing everyday gadgets has become a genuine part of protecting the wider internet. Some of the largest recorded denial-of-service attacks have drawn on huge numbers of hijacked connected devices, showing how ordinary household hardware can be turned into serious infrastructure for crime.

The bottom line

A botnet is an army of hijacked devices under one attacker’s remote control, powerful precisely because it acts in coordinated numbers. It gets its orders through a command-and-control system that can be centralized or peer-to-peer, and it fuels attacks from massive DDoS floods to spam and data theft. Since infected devices usually show few signs, the strongest defense is prevention: strong passwords, prompt updates, and caution with what you click.

Sources

Adrian Cole

Editor-in-Chief

Adrian Cole is the Editor-in-Chief of Cubed News, where he holds final responsibility for what the publication says and how it says it. His remit runs across every desk — politics, business, technology, world news, health, science, opinion and culture — and… More from this editor →

Related from Technology

Get Cubed News in your inbox

Daily premium coverage, free. Independent · Source-cited.