# What is a Botnet?

> A botnet is a collection of compromised or otherwise illicitly controlled connected systems that an operator coordinates to perform tasks at scale.

- Canonical URL: https://yellowcube.eu/glossary/botnet/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Its bots can be personal devices, servers, routers, cameras, cloud workloads, or other networked equipment, often without their owners’ knowledge. A shared command-and-control mechanism distinguishes a malicious botnet from ordinary distributed computing.

Control can be centralized, hierarchical, peer-to-peer, or distributed through legitimate online services. Operators may change infrastructure and issue different tasks over time, including distributed denial-of-service attacks, spam, credential abuse, proxying, fraud, data collection, or malware delivery. One malware family can support several separately operated botnets.

### Key points

- **Formation:** Devices may be recruited through exploitable services, weak or reused credentials, malicious software, supply-chain compromise, or unauthorized cloud and hosting accounts.
- **Evidence:** Repeated callbacks, synchronized actions, known control protocols, unexpected peer traffic, configuration changes, scanning, spam, or attack traffic can support identification when correlated with host evidence.
- **Disruption and recovery:** Blocking or sinkholing control infrastructure can reduce activity, but owners still need to remove malicious access, remediate the entry path, rotate exposed credentials, and restore trustworthy configuration.
- **Important limitation:** A suspicious address, traffic spike, or threat-intelligence match does not prove that a device remains an active bot. Shared addresses, reassigned infrastructure, stale lists, and spoofed or reflected traffic complicate attribution and counting.

### Related terms

[Malware](<https://yellowcube.eu/glossary/malware/>) · [Command and control (C2)](<https://yellowcube.eu/glossary/command-and-control/>) · [Distributed denial-of-service (DDoS) attack](<https://yellowcube.eu/glossary/distributed-denial-of-service-attack/>) · [Distributed denial-of-service (DDoS) mitigation](<https://yellowcube.eu/glossary/distributed-denial-of-service-mitigation/>) · [IoT security](<https://yellowcube.eu/glossary/iot-security/>) · [Cryptojacking](<https://yellowcube.eu/glossary/cryptojacking/>)

### Sources

[CISA NICCS Glossary: Botnet](https://niccs.cisa.gov/about-niccs/glossary) · [U.S. Department of Commerce and Department of Homeland Security: Enhancing Resilience Against Botnets](https://csrc.nist.gov/files/pubs/other/2018/05/30/enhancing-resilience-against-botnetsreport-to-the-/final/docs/eo_13800_botnet_report_-_finalv2.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

