Botnet: an army of compromised machines
A botnet is a network of infected machines—computers, servers, connected objects—remotely controlled by an attacker without their owners' knowledge and collectively mobilized to carry out malicious actions.
Definition
Each infected machine (a “bot”) receives instructions from a command-and-control (C2) server. Taken individually, a compromised machine may seem harmless; grouped by the thousands or millions, they create considerable attack capacity, especially for distributed denial-of-service attacks.
Botnets are also used for mass spam sending, cryptocurrency mining without victims' knowledge, or campaigns of credential stuffing. Their detection often relies on observing abnormal outbound network traffic from compromised machines.
Key points
Centralized, remote control
A command-and-control server remotely drives all infected machines in the botnet.
Massive attack capacity
When grouped together, individually harmless machines form a strike force used especially for DDoS attacks.
Revealing outbound traffic
A machine integrated into a botnet often generates abnormal outbound network traffic, detectable through appropriate monitoring.
How BCIT can support you
We support compromise detection and protection against denial-of-service attacks powered by botnets.
Frequently asked questions ❓
How can I tell if my machine is part of a botnet?
Abnormal outbound network traffic, unexplained slowness, or connections to unknown servers are warning signs to monitor.
Are botnets only used for DDoS attacks?
No. They are also used to send spam, mine cryptocurrency, or run credential stuffing campaigns.
Not ready to talk yet? Discover our cybersecurity assessment →
Could your machines be part of a botnet without your knowledge?
An audit of your network traffic can detect a potential silent compromise.
Botnet: an army of compromised machines
A botnet is a network of infected machines—computers, servers, connected objects—remotely controlled by an attacker without their owners' knowledge and collectively mobilized to carry out malicious actions.
Definition
Each infected machine (a “bot”) receives instructions from a command-and-control (C2) server. Taken individually, a compromised machine may seem harmless; grouped by the thousands or millions, they create considerable attack capacity, especially for distributed denial-of-service attacks.
Botnets are also used for mass spam sending, cryptocurrency mining without victims' knowledge, or campaigns of credential stuffing. Their detection often relies on observing abnormal outbound network traffic from compromised machines.
Key points
Centralized, remote control
A command-and-control server remotely drives all infected machines in the botnet.
Massive attack capacity
When grouped together, individually harmless machines form a strike force used especially for DDoS attacks.
Revealing outbound traffic
A machine integrated into a botnet often generates abnormal outbound network traffic, detectable through appropriate monitoring.
How BCIT can support you
We support compromise detection and protection against denial-of-service attacks powered by botnets.
Frequently asked questions ❓
How can I tell if my machine is part of a botnet?
Abnormal outbound network traffic, unexplained slowness, or connections to unknown servers are warning signs to monitor.
Are botnets only used for DDoS attacks?
No. They are also used to send spam, mine cryptocurrency, or run credential stuffing campaigns.
Not ready to talk yet? Discover our cybersecurity assessment →
Could your machines be part of a botnet without your knowledge?
An audit of your network traffic can detect a potential silent compromise.