Skip to content

Botnet / Bot

Risk Level

A botnet (robot network) is a collection of compromised devices (bots) controlled by a bot herder via Command & Control (C2) infrastructure. Botnets provide distributed compute power for DDoS, spam, credential stuffing, cryptomining, proxy networks, and as a platform for deploying secondary payloads.

MilestoneYearDetails
GTbot2000First IRC-based botnet
Agobot/Phatbot2002Modular, C++ source leaked
SDBot/RBot2003Source leaked; many variants
Storm Worm2007P2P C2; 1-10M bots
Conficker200810M+; DGA; massive scale
Zeus/Zbot2007+Banking + botnet
Mirai2016IoT botnet; 600K+; Dyn DDoS
Emotet2014+Loader → botnet; spam, ransomware
TrickBot2016+Modular; banking → ransomware
Qakbot2007+Banking → ransomware delivery
┌─────────────────┐
│ BOT HERDER │ (C2 Operator)
└────────┬────────┘
│ C2 Commands
┌─────────────────┐
│ C2 INFRASTRUCTURE │ (HTTP, DNS, P2P, Tor, Blockchain)
└────────┬────────┘
│ Encrypted C2 Traffic
┌────┴────┐
▼ ▼
┌──────┐ ┌──────┐
│ BOT │ │ BOT │ ... (Compromised Devices)
└──────┘ └──────┘
TopologyDescriptionExamples
CentralisedAll bots → single C2 serverEarly botnets (Agobot)
Tiered / ProxyBots → proxies → C2Zeus, Gameover Zeus
P2PBots ↔ bots; no central serverStorm, ZeroAccess, Gameover
HybridCentralised fallback + P2PConficker, Gameover Zeus
Domain Generation (DGA)Algorithmic domain listConficker, Mirai variants
Fast FluxRapid DNS IP rotationFast flux botnets
Tor / I2PHidden service C2Tor-based botnets
BlockchainOP_RETURN, smart contractsMemo.cash, Ethereum logs
BotnetYearArchitectureNotable
Storm2007P2P1-10M bots
Conficker2008DGA + P2P10M+; MS08-067
Mirai2016CentralisedIoT; Dyn DDoS
Necurs2012+Centralised6M+; spam, ransomware
Emotet2014+TieredLoader → botnet
TrickBot2016+TieredBanking → ransomware
Qakbot2007+TieredBanking → ransomware
Mozi2019+P2PIoT, DGA
ActivityDescription
DDoSVolumetric, application layer, reflection
SpamEmail, SMS, social media
Credential StuffingAutomated login attempts
CryptominingXMR, ETH, CPU/GPU
Proxy/VPNResidential proxy networks (e.g., 911 S5)
Click FraudAd click automation
Ransomware DeliveryEmotet → Ryuk, TrickBot → Conti
Data ExfiltrationStaging for theft
  • Patch IoT/routers — Default creds, UPnP, firmware
  • Network segmentation — IoT on isolated VLAN
  • Egress filtering — Block unusual outbound
  • DNS filtering — Block DGA, known C2 domains
  • EDR on endpoints — Detect bot processes
  • NetFlow/Zeek monitoring — Beaconing detection
  • Sinkhole DGA domains — Pre-register or block
TechniqueIDDescription
BotnetT1583.005Acquire botnet infrastructure
C2T1071Command & Control
ProxyT1090Proxy traffic through bots
DDoST1498Network/service disruption
  • Worm — Self-propagation
  • DDoS — Volumetric attacks
  • Mirai — IoT botnet case study