
Botnet
A botnet is a large group of other people's computers that have been secretly infected with malware and are remotely controlled by criminals. The owners usually notice nothing, while their devices are abused for attacks, spam emails, or fraud.
A botnet is a network of many devices belonging to other people that someone secretly controls remotely. A malicious program has previously found its way onto each of these devices without the owner noticing. This program stays quietly in the background and waits for commands from the internet. When a command arrives, all devices carry it out simultaneously. This turns thousands of ordinary computers, phones, or surveillance cameras into a single large attack machine. The name is made up of “robot” and “network,” because the devices obey like remote-controlled machines.
Why hijacked devices become a weapon
A single infected laptop causes little damage. The danger comes from sheer numbers. Large botnets comprise hundreds of thousands to millions of devices, spread across the entire world. Together they muster enough computing power and internet connections to bring down even large companies.
The most common application is a so-called DDoS attack. In this, all hijacked devices access the same website at the same time. The server receives millions of requests per second and collapses under the load. For real users, the site then becomes unreachable. Some gangs rent out this capacity by the hour to paying customers.
But botnets also serve quieter businesses. They send advertising and fraud emails, crack passwords through mass trial and error, or automatically click on ads to siphon off advertising revenue. Because the traffic comes from genuine private connections, it is hard for defense systems to distinguish from normal users. This is precisely where the economic value for the attackers lies.
From infected device to command
It all starts with the infection. A user opens an email attachment, installs a program from a dubious source, or visits a compromised website. Even more often, the malware itself searches for devices with outdated software or an unchanged default password. Networked everyday devices such as routers, cameras, or printers are especially vulnerable. They stay connected to the network for years without ever receiving an update.
Afterward, the device reports to a control server known as a command-and-control server. Through this channel, the operator issues instructions. Think of it like a radio channel that all devices are listening to. When the operator says “attack this address,” they all start at once.
Because a single control server can easily be shut down, modern botnets make their control more robust. Some pass commands from device to device, without any fixed central hub at all. Others hide their commands within perfectly normal web traffic or in social media posts. A common misconception is that an infected computer becomes noticeably slower. Good malware deliberately throttles itself so that no one becomes suspicious.
Botnets in the news and in your own household
Botnets regularly appear in business news when online shops, banks, or government websites go down for hours. The Mirai botnet became well known in 2016, taking over mainly unsecured cameras and routers. It temporarily crippled large parts of well-known services in the USA. Since then, investigators and security firms keep announcing the takedown of large networks, often through international cooperation.
The term also comes up in connection with artificial intelligence. Automatically generated texts make fraudulent emails more convincing, and hijacked devices help distribute them en masse. Conversely, defense systems themselves rely on machine learning methods to detect suspicious traffic patterns early.
In everyday life, protection is surprisingly simple. Install updates, change default passwords on routers and cameras, and don’t install programs from unclear sources. Anyone who does this becomes a noticeably less attractive target for automated infection attempts. After all, botnet operators rarely target specific individuals; they simply take whatever is unsecured and reachable on the network.