What are Botnets?
Botnets—a combination of the words “robot” and “network”—are networks of hijacked computers and internet-connected devices that are infected by malware (i.e., malicious software). The malware runs bots on the compromised devices without the knowledge of device users.
Botnets are usually controlled by a botmaster or bot herder. The bot herder turns these hijacked computer devices into remote-controlled “zombie” computers. By linking compromised devices in large numbers, it becomes possible to create botnets that can be leveraged against various targets to carry out distributed denial of service (DDoS) attacks, account takeover, data theft and several other types of attacks.
Editor's note: This article has been updated to include new botnet examples and trends in botnet detection in 2026.
In this article:
What is an IoT Botnet? | A Radware Minute
Botnets are used by threat actors for several types of malicious activity:
Email spam: Botnets have often been used to widely distribute email spam. This allows for drive-by downloads triggered without user intervention, phishing links that fool unsuspecting users into clicking and automatically installing malware, and various other malicious acts.
Financial breaches: Botnets are known to have infiltrated financial institutions including banks and payment processors to exfiltrate confidential consumer and business data, which can be further used to carry out other forms of fraud.
Information theft: Malicious actors have used botnets to cast a wide net to steal personal and organizational data which can be further abused to carry out fraud, impersonation, blackmail and financial crimes.
Targeted intrusions: Botnets can be used to execute credential stuffing attacks, in which lists of breached and stolen username and password pairs are rapidly entered to gain access to devices and user accounts, both on devices and websites or applications. In a similar manner, botnets can also be used for credential cracking attacks, in which random passwords are generated and entered in the hope of eventually guessing the correct password.
DDoS attacks: Botnets have been responsible for some of the most large-scale distributed denial of service (DDoS) attacks. Through their sheer volume, these attacks can slow down unprotected networks and servers, and disrupt the normal functioning of websites, mobile applications, and APIs. DDoS attacks have often been linked to criminal networks and nation states with the intention of crippling or even bringing down their adversaries' networks. They can affect the normal functioning of public goods such as power, water, sanitation systems, financial institutions, marketplaces and other types of targets that can cause inconvenience, disruption, or frustration to their users.
Ad fraud: Botnets have been used to execute ad fraud, in which legitimate ads and their embedded links are replaced by fraudulent ads with embedded links that bring traffic (and potentially, revenue) to websites controlled by the bot herder. Botnets are also used to generate fake clicks on ads to generate false impressions and game the ad-tech ecosystem for profit.
Crypto-currency mining and fraud: Botnets can leverage the processing power of thousands or even millions of infected devices to mine crypto-currencies and steal access to coin lockers or wallets.
Bot herders create botnets by spreading malware to infect PCs, smartphones and internet of things (IoT) devices including security cameras, smoke detectors, digital video recorders and many other smart devices. This is achieved through various means such as social engineering, website and application vulnerabilities, exploit kits, and Trojan software which infect targeted devices without alerting their owners.
Exploit kits can be purchased on the dark web or created by hackers and are often concealed in seemingly legitimate downloadable files, including free software, music, or video content. Malware can even be of the self-installing “drive-by” type that is widespread on shady websites, and doesn’t even need to be clicked on to infect a device.
After the bot software is installed on compromised zombie computers, they are ready to receive commands from their bot herders to execute actions based on the intentions of their controller. The controller of a botnet can direct its activities through communication channels based on network protocols such as IRC and HTTP, both as peer-to-peer networks or directed by a central command and control (C&C) device.
Distributed Denial-of-Service (DDoS) Attacks
In a DDoS attack, the bot herder instructs the botnet to flood a target server or network with excessive traffic, overwhelming its capacity and causing service disruptions. By sending massive amounts of requests simultaneously from thousands of compromised devices, the attack prevents legitimate users from accessing the service.
Botnets carrying out DDoS attacks have affected large-scale targets, including government websites, online gaming platforms, and financial institutions, often resulting in downtime and financial loss.
Spam Distribution
Botnets are frequently used to distribute spam emails, which can contain malicious attachments, phishing links, or other harmful content designed to deceive recipients. By sending spam from a vast number of infected devices, bot herders can bypass spam detection mechanisms and amplify the reach of their campaigns.
Spam botnets are also used for “drive-by downloads,” where malicious software installs automatically when recipients open certain emails, further expanding the botnet.
Credential Theft
Botnets facilitate credential theft by running large-scale attacks aimed at harvesting login details for accounts. This includes credential stuffing, where breached usernames and passwords are repeatedly tested against various services to gain unauthorized access.
Botnets may also use keyloggers to capture keystrokes, stealing credentials from infected devices directly. Stolen credentials are often sold on underground markets or used to conduct identity theft, fraud, and further cyberattacks.
Click Fraud
Click fraud botnets manipulate online advertising by generating fake clicks on ads, making it appear as though users are engaging with the content. Each infected device mimics genuine user behavior, driving fraudulent ad impressions or clicks that lead to ad revenue for the bot herder.
This threat costs advertisers millions in wasted ad spend and also undermines the integrity of the ad-tech ecosystem by skewing performance data and inflating campaign costs.
Cryptocurrency Mining
Botnets can also be used for illegal cryptocurrency mining by exploiting the processing power of infected devices. Each compromised device in the botnet contributes its CPU or GPU resources to mining cryptocurrencies like Bitcoin or Monero, without the device owner’s knowledge.
This unauthorized mining can degrade device performance, increase electricity costs, and reduce the lifespan of the hardware. Mining botnets are highly profitable for attackers, especially when they consist of thousands of high-performance infected devices.
Botnets can perform the same functions as individual bots, but on a far larger scale. They're able to carry out often overwhelming attacks on their targets. Though most conventional bots are based on scripts and web browsers, botnets can also be built on malicious software that is designed for rapid infestation across many vulnerable devices.
Once installed, the botnet software can often function with administrative privileges on the infected device. This gives bot herders virtually unhindered access to the device’s memory, processor, data storage and allows the botnet controller to remotely execute any actions that the device user is capable of performing.
Botnets are capable of:
- Reading and writing system data
- Gathering personal data from infected devices
- Sending files and other data
- Monitoring users’ activities
- Searching for vulnerabilities in other devices
- Installing and running any applications
Command and Control (C&C) of botnets are generally carried out by two methods:
Centralized: The Client-Server Botnet Model
The first known botnets initially used to be exclusively controlled using client-server models in which a domain, website, or Internet Relay Chat channel controlled by the bot herder is contacted by the bot software on infected devices to both receive orders and transmit data back to the controller. This centralized command model is rarely used anymore as various global law enforcement and security agencies have tracked and shut down their central servers in recent years, thus crippling botnets that were based on this model.
Decentralized: The Peer-to-Peer Botnet Model
Due to aggressive action by security agencies in cracking down on centralized C&C botnet servers around the world, the decentralized P2P model is now almost universally used to control botnets. This eliminates centralized control which has a single point of failure that is vulnerable to being shut down by law enforcement agencies and replaces it with decentralized peer-to-peer control.
P2P botnets find other infected devices by scanning random IP addresses to establish contact. If a machine is infected, it conveys its list of installed bots to the infected machine that contacted it, which can then relay updates and commands from the botnet controller to herd the new additions to the botnet to execute commands.
As bot technology becomes more advanced, botnets are growing in size, speed, and sophistication. Modern botnets are no longer limited to infected desktop computers. They can include internet-connected cameras, routers, servers, mobile devices, proxy networks, and compromised cloud infrastructure. Some are used for DDoS attacks, while others are designed for ad fraud, credential theft, proxy abuse, ransomware delivery, or state-sponsored espionage.
Below are several major botnet-related attacks and operations that show how botnets have evolved over time.
Mirai Botnet
The Mirai botnet was discovered in 2016 and became one of the most well-known Internet of Things botnets. It infected poorly secured IoT devices such as routers, IP cameras, and digital video recorders by scanning for devices that still used default or weak login credentials.
Mirai was used in massive DDoS attacks, including attacks against OVH, a French hosting provider, and Dyn, a major DNS provider. The Dyn attack disrupted access to major websites and online services, including Netflix, Twitter, Reddit, GitHub, and others.
Lesson learned: IoT devices can become powerful attack tools when they are shipped with weak default credentials, left unpatched, or exposed directly to the internet. Organizations and consumers should change default passwords, update device firmware, disable unnecessary remote access, and avoid using unsupported devices.
3ve Botnet
3ve was a large ad-fraud operation that used infected computers and hijacked IP addresses to generate fake advertising traffic. The botnet loaded fake webpages, created fraudulent ad impressions, and made advertisers pay for views that did not come from real users.
The operation involved large numbers of compromised devices and fake websites, generating tens of millions of dollars in fraudulent advertising revenue before it was taken down through cooperation between law enforcement and private cybersecurity companies.
Lesson learned: Botnets are not used only for DDoS attacks. They can also quietly monetize infected devices through fraud. Digital advertising platforms need strong fraud detection, traffic validation, publisher verification, and cross-industry threat intelligence sharing.
Mantis Botnet
Mantis was a powerful botnet reported in 2022 and linked to record-setting HTTPS DDoS attacks. Unlike many botnets that rely mainly on low-powered IoT devices, Mantis used a relatively small number of compromised servers. Because servers have more processing power than typical consumer devices, the botnet could generate extremely large volumes of encrypted HTTPS traffic.
Cloudflare reported mitigating an HTTPS DDoS attack that reached 26 million requests per second. The attack showed how even a smaller botnet can be highly destructive if the infected machines are powerful enough.
Lesson learned: Botnet strength is not measured only by the number of infected devices. A smaller botnet made of powerful servers can be more dangerous than a much larger botnet made of weak devices. Defenders need application-layer DDoS protection, automated traffic filtering, and strong server-hardening practices.
HTTP/2 Rapid Reset Attacks
HTTP/2 Rapid Reset was not a botnet itself, but a protocol-level attack technique that was used to launch record-breaking DDoS attacks. Attackers abused the HTTP/2 stream reset feature to rapidly open and cancel large numbers of requests, overwhelming web servers and application infrastructure.
These attacks reached hundreds of millions of requests per second and affected major internet infrastructure providers. Because HTTP/2 is widely used by modern websites and applications, the vulnerability created a serious risk for many online services.
Lesson learned: Even well-established web protocols can contain weaknesses that attackers can exploit at massive scale. Organizations should keep web servers, proxies, load balancers, and CDN configurations updated, and should rely on layered DDoS defenses that can absorb attacks at the network edge.
911 S5 Botnet
The 911 S5 botnet was one of the largest known residential proxy botnets. It compromised millions of devices and allowed criminals to route traffic through real residential IP addresses. This helped attackers hide their identities and make malicious activity appear as if it came from ordinary home users.
The botnet was used to support many types of cybercrime, including fraud, identity theft, credential attacks, and other illegal activity. In 2024, an international law enforcement operation dismantled the botnet and arrested its alleged administrator.
Lesson learned: Botnets can be used as anonymity infrastructure, not just attack infrastructure. Residential proxy abuse makes fraud harder to detect because traffic appears to come from legitimate users. Security teams should monitor suspicious login patterns, impossible travel, abnormal session behavior, and repeated activity from residential IP ranges.
Raptor Train Botnet
Raptor Train was a large IoT and small-office/home-office botnet publicly detailed in 2024. It compromised devices such as routers, IP cameras, digital video recorders, and network-attached storage devices. Researchers described it as a sophisticated, multi-tiered botnet with command-and-control infrastructure designed to manage large numbers of infected devices.
The botnet was linked to targeting activity involving government, military, telecommunications, higher education, defense, and IT sectors. Researchers assessed that it was likely operated by a Chinese state-sponsored threat actor. Even where DDoS activity was not always observed, the scale and structure of the botnet made it a serious platform for espionage, scanning, exploitation, and potential future disruption.
Lesson learned: Botnets are increasingly used by advanced threat actors, not just cybercriminals. Old routers, cameras, and unsupported network devices can become long-term footholds for espionage or pre-positioning. Organizations should inventory exposed devices, replace end-of-life hardware, segment networks, and monitor unusual outbound traffic from edge devices.
GorillaBot
GorillaBot, also called Gorilla, was reported in 2024 as a Mirai-inspired botnet focused on DDoS attacks. It supported multiple CPU architectures, allowing it to infect a wide range of devices. Researchers reported that it issued more than 300,000 attack commands in less than a month and targeted organizations across more than 100 countries.
Its targets included universities, government websites, telecommunications providers, banks, gaming platforms, and gambling-related services. The botnet used several DDoS methods, including UDP floods, SYN floods, ACK floods, and other traffic-generation techniques.
Lesson learned: Mirai-style malware continues to evolve because attackers can reuse leaked code and adapt it to new devices and vulnerabilities. Defenders should not treat older malware families as solved problems. Continuous patching, traffic anomaly detection, rate limiting, and upstream DDoS mitigation remain essential.
Aisuru/Kimwolf Botnet
Aisuru/Kimwolf was associated with large-scale DDoS activity reported in 2025 and 2026. Cloudflare described a major campaign in late 2025 that used infected Android TVs and other IoT devices to generate hyper-volumetric HTTP DDoS attacks. Some attacks exceeded 200 million requests per second, and Cloudflare also reported a record-breaking 31.4 Tbps attack during the broader period.
In 2026, U.S. authorities announced actions to disrupt command-and-control infrastructure associated with Aisuru, KimWolf, JackSkid, and Mossad IoT botnets. These botnets infected millions of devices and were used in cybercrime-as-a-service operations, allowing customers to rent attack capacity for DDoS campaigns.
Lesson learned: Consumer IoT devices, including smart TVs and home networking equipment, can be abused at global scale. Manufacturers need secure-by-default designs, automatic updates, and longer support lifecycles. Users and organizations should isolate IoT devices, remove unsupported hardware, and monitor for unusual outbound traffic.
Rapper Bot
Rapper Bot was a DDoS-for-hire botnet disrupted by U.S. authorities in 2025. According to court documents, it infected tens of thousands of devices, including DVRs and Wi-Fi routers, and was rented to paying customers who used it to launch DDoS attacks.
Authorities alleged that Rapper Bot was used in more than 370,000 attacks against 18,000 victims in over 80 countries. Some attacks reportedly measured between two and three terabits per second, with the largest possibly exceeding six terabits per second.
Lesson learned: DDoS-for-hire services lower the barrier to cybercrime by allowing customers to rent botnet power without building malware themselves. Law enforcement disruption helps, but organizations still need proactive DDoS readiness, including incident response plans, traffic scrubbing, CDN protection, and coordination with hosting providers and ISPs.
The botnet detection market is growing rapidly as botnet attacks become larger, more automated, and harder to identify with traditional security tools. Market projections show strong expansion, driven by rising DDoS activity, the growth of insecure IoT devices, API-focused attacks, and the increasing use of AI by both attackers and defenders.
Here are recent trends in botnet detection, indicated by recent research:
- Strong market growth: The global botnet detection market is projected to grow from about $899.92 million to $5.19 billion by 2031.
- More powerful DDoS attacks: Terabit-scale DDoS attacks are now occurring five times more often than the previous year, often using compromised broadband connections and large botnet networks.
- Automated traffic is increasing: Automated traffic now accounts for around 51% of all internet traffic, making it harder to distinguish malicious bots from legitimate users.
- IoT devices are expanding the attack surface: Poorly secured IoT devices are frequently compromised and added to botnets. IoT malware attacks rose by 124% in one year, highlighting the scale of the problem.
- False positives remain a major challenge: Detection systems can mistakenly block legitimate traffic, creating risks for revenue, customer experience, and business continuity.
- API attacks are becoming a priority: Attackers are increasingly targeting APIs for data scraping, account takeover, and abuse of business logic. Reports show around 150 billion API attacks over a two-year period.
- AI-driven detection is becoming essential: Static rules and signature-based tools are less effective against adaptive botnets. Machine learning is now used to analyze behavior, traffic patterns, and user interactions in real time.
- AI is also improving attacks: Attackers are using AI to optimize credential stuffing and account takeover attempts. Account takeover attacks recently increased by 40% in one year, pushing organizations toward more predictive detection solutions.
1. Network Security Measures
Implementing strong network security measures is crucial for defending against botnets. A well-configured firewall can block malicious traffic from entering the network, and intrusion detection systems (IDS) or intrusion prevention systems (IPS) can monitor traffic for suspicious patterns.
Network segmentation helps isolate critical systems, limiting the spread of malware if a device is compromised. Regular network traffic analysis is essential for detecting anomalies, such as unusual communication patterns indicative of botnet activity. Organizations should also regularly patch network devices like routers and switches to close vulnerabilities that botmasters might exploit.
2. Bot Management
Effective bot management is key to preventing botnet attacks and mitigating their impact. One approach involves deploying advanced bot detection tools that can differentiate between legitimate users and automated bot traffic based on behavioral analysis. These tools use machine learning algorithms to recognize anomalies in request patterns, device characteristics, and session activity, helping to identify and block malicious bots in real-time.
Integrating bot management solutions with web application firewalls (WAFs) can provide an added layer of security, blocking requests from known botnet IP addresses and suspicious traffic sources. Another crucial aspect of bot management is rate limiting and CAPTCHA enforcement. By implementing rate limiting, organizations can restrict the number of requests a user or bot can make within a given timeframe, reducing the impact of automated attacks. CAPTCHA tests are effective against simple bots that cannot solve human verification challenges, deterring many types of automated abuse.
3. Endpoint Protection
Endpoint protection is critical to stop botnets from infecting individual devices. Using a comprehensive endpoint detection and response (EDR) solution ensures that all devices connected to the network are monitored for malware, suspicious behavior, and known botnet signatures.
Antivirus and anti-malware software should be kept up to date on all endpoints to detect and remove threats. Additionally, organizations should enforce strict policies for software installation, requiring users to only install applications from trusted sources. Regular device scanning and patch management practices further reduce the risk of malware infections.
4. Email and Web Filtering
Many botnets propagate through phishing emails and malicious websites. Email filtering solutions can block phishing emails and attachments that contain malware. These filters scan incoming messages for indicators of compromise, such as suspicious links, untrusted domains, or known malicious attachments.
Similarly, web filtering software can prevent users from accessing malicious websites where botnet malware might be hosted. By blocking access to high-risk domains and URLs, web filters protect against drive-by downloads that could compromise a device without user interaction.
5. Access Controls and Authentication
Implementing robust access controls and multi-factor authentication (MFA) can prevent botmasters from exploiting compromised credentials to expand their botnets. Role-based access controls (RBAC) should be employed to limit access to sensitive systems and data, ensuring that even if a botnet compromises a device, its access is restricted.
MFA adds an additional layer of security, requiring more than just a password for authentication. This significantly reduces the likelihood of successful credential stuffing or brute-force attacks orchestrated by botnets.
6. User Awareness Training
Educating users is a fundamental defense against botnets. User awareness training should focus on identifying phishing emails, avoiding suspicious downloads, and practicing good cybersecurity hygiene, such as using strong, unique passwords. Regular simulations of phishing attacks can help reinforce this training.
Users should also be trained to report any unusual device behavior, which could indicate that a botnet has compromised their machine. By fostering a security-conscious culture, organizations can minimize human errors that lead to malware infections.
7. DDoS Mitigation
Organizations should implement DDoS mitigation strategies to protect against botnet-driven attacks. This includes deploying DDoS protection services, such as cloud-based scrubbing solutions, which can absorb and filter out malicious traffic before it reaches the target network. Rate limiting and traffic shaping can also help manage excessive traffic loads during an attack.
Additionally, working with internet service providers (ISPs) to reroute traffic during an attack can help maintain service availability. Regularly testing DDoS response plans ensures that the organization is prepared to respond quickly and effectively if an attack occurs.
Bot Mitigation
The most crucial security defense against botnets is a solution such as Radware Bot Manager. Our solution leverages a combination of Radware’s patented intent-based deep behavioral analysis, collective bot intelligence, semi-supervised machine learning, device and browser fingerprinting, and anomaly detection based on variance from normal user flows.
Account Takeover (ATO) Protection
Radware Bot Manager protects against Account Takeover attacks, and offers robust protection against unauthorized access to user accounts across web portals, mobile applications, and APIs. Utilizing advanced techniques such as Intent-based Deep Behavior Analysis (IDBA), semi-supervised machine learning, device fingerprinting, and user behavior modeling, it ensures precise bot detection with minimal false positives. The solution provides comprehensive defense against brute force and credential stuffing attacks, and offers flexible bot management options including blocking, CAPTCHA challenges, and feeding fake data. With a scalable infrastructure and a detailed dashboard, Radware Bot Manager delivers real-time insights into bot traffic, helping organizations safeguard sensitive data, maintain user trust, and prevent financial fraud.
DDoS Protection
In addition to bot detection and mitigation, solutions such as Radware’s Cloud DDoS Protection Service and DefensePro are an essential component to prevent DDoS attacks, which are one of the hallmark applications of malicious botnets.