A botnet (robot network) is a collection of compromised devices (bots) controlled by a bot herder via Command & Control (C2) infrastructure. Botnets provide distributed compute power for DDoS, spam, credential stuffing, cryptomining, proxy networks, and as a platform for deploying secondary payloads.
Milestone Year Details GTbot 2000 First IRC-based botnet Agobot/Phatbot 2002 Modular, C++ source leaked SDBot/RBot 2003 Source leaked; many variants Storm Worm 2007 P2P C2; 1-10M bots Conficker 2008 10M+; DGA; massive scale Zeus/Zbot 2007+ Banking + botnet Mirai 2016 IoT botnet; 600K+; Dyn DDoS Emotet 2014+ Loader → botnet; spam, ransomware TrickBot 2016+ Modular; banking → ransomware Qakbot 2007+ Banking → ransomware delivery
│ BOT HERDER │ (C2 Operator)
│ C2 INFRASTRUCTURE │ (HTTP, DNS, P2P, Tor, Blockchain)
│ BOT │ │ BOT │ ... (Compromised Devices)
Topology Description Examples Centralised All bots → single C2 server Early botnets (Agobot) Tiered / Proxy Bots → proxies → C2 Zeus, Gameover Zeus P2P Bots ↔ bots; no central server Storm, ZeroAccess, Gameover Hybrid Centralised fallback + P2P Conficker, Gameover Zeus Domain Generation (DGA) Algorithmic domain list Conficker, Mirai variants Fast Flux Rapid DNS IP rotation Fast flux botnets Tor / I2P Hidden service C2 Tor-based botnets Blockchain OP_RETURN, smart contracts Memo.cash, Ethereum logs
Botnet Year Architecture Notable Storm 2007 P2P 1-10M bots Conficker 2008 DGA + P2P 10M+; MS08-067 Mirai 2016 Centralised IoT; Dyn DDoS Necurs 2012+ Centralised 6M+; spam, ransomware Emotet 2014+ Tiered Loader → botnet TrickBot 2016+ Tiered Banking → ransomware Qakbot 2007+ Tiered Banking → ransomware Mozi 2019+ P2P IoT, DGA
Activity Description DDoS Volumetric, application layer, reflection Spam Email, SMS, social media Credential Stuffing Automated login attempts Cryptomining XMR, ETH, CPU/GPU Proxy/VPN Residential proxy networks (e.g., 911 S5) Click Fraud Ad click automation Ransomware Delivery Emotet → Ryuk, TrickBot → Conti Data Exfiltration Staging for theft
✅ Patch IoT/routers — Default creds, UPnP, firmware
✅ Network segmentation — IoT on isolated VLAN
✅ Egress filtering — Block unusual outbound
✅ DNS filtering — Block DGA, known C2 domains
✅ EDR on endpoints — Detect bot processes
✅ NetFlow/Zeek monitoring — Beaconing detection
✅ Sinkhole DGA domains — Pre-register or block
Technique ID Description Botnet T1583.005 Acquire botnet infrastructure C2 T1071 Command & Control Proxy T1090 Proxy traffic through bots DDoS T1498 Network/service disruption
Worm — Self-propagation
DDoS — Volumetric attacks
Mirai — IoT botnet case study