Botnet

A network of compromised devices, each a bot, that an attacker directs remotely through command-and-control channels to run coordinated activity such as DDoS attacks, spam or credential stuffing.

A botnet is a collection of compromised computers, servers or Internet of Things devices, each running malware that lets a remote operator direct it. Each infected device is a bot, sometimes called a zombie, and the operator is often called the bot herder. The owners of the devices commonly do not know they are involved. Instructions travel through command and control (C2) infrastructure, which may be a few central servers or a peer-to-peer design with no single point to take down.

A botnet turns many small resources into one large one. It is commonly used for distributed denial of service attacks, where many bots send traffic at once, sometimes combined with amplification. Botnets are also used for spam, credential stuffing, click fraud and spreading further malware. The defences an organisation controls are keeping its own devices out of botnets (patching, removing default credentials, endpoint security) and spotting infected hosts through egress monitoring and egress filtering of their outbound C2 traffic.

Exam relevance: a scenario is likely to describe internal hosts making regular outbound connections to an unknown server, or taking part in an attack on a third party. Candidates are expected to recognise bots under remote control, and to see that an organisation’s hosts can be victims and, unknowingly, attackers at the same time.