September 10, 2026

What Is a Botnet and How Can You Protect Your Business?

Beware of Botnets

Botnets are still a threat to connected devices

A botnet is a network of computers, routers, servers, or other connected devices that have been infected with malware and placed under an attacker's control.

Once compromised, these devices can be used together to carry out cyberattacks without their owners realizing what is happening.

Botnets can be used to:

  • Launch distributed denial-of-service (DDoS) attacks
  • Send spam or phishing messages
  • Distribute additional malware
  • Steal credentials or other information
  • Create fraudulent traffic
  • Support other criminal activity
  • Use compromised devices as part of a larger attack

Botnets aren't limited to traditional computers. Connected devices such as routers, security appliances, cameras, and other IoT devices can also become part of a botnet when they are vulnerable or poorly secured.

The FBI has documented botnet campaigns involving thousands of devices used by small and midsize businesses. In one example, the Cyclops Blink malware compromised network security devices used by organizations around the world before a coordinated disruption operation removed the malware from affected devices.

How does a botnet work?

A botnet generally begins when an attacker compromises a device.

The attacker may exploit a software vulnerability, use stolen credentials, distribute malware through phishing, or take advantage of weak security configurations.

Once malware is installed, the device can communicate with infrastructure controlled by the attacker. The compromised device becomes a bot, sometimes called a zombie device.

The attacker can then coordinate many compromised devices as a single network.

A simplified botnet attack looks like this:

  1. Infection: Malware compromises a device.
  2. Connection: The infected device connects to the attacker's command-and-control infrastructure.
  3. Expansion: The attacker compromises additional devices.
  4. Coordination: The infected devices receive instructions.
  5. Attack: The botnet is used to carry out malicious activity.

The owner of an infected device may not immediately notice anything unusual.

What can a botnet do?

The purpose of a botnet depends on the attacker's goals.

Launch DDoS attacks

One of the most recognizable uses of a botnet is a distributed denial-of-service attack.

The attacker directs large numbers of compromised devices to send traffic or requests to a target. The resulting volume can overwhelm a website, application, network, or online service.

Spread malware

Botnets can also help attackers distribute additional malicious software.

For example, a compromised computer could be instructed to download ransomware, credential-stealing malware, or other malicious programs.

Steal information

Some malware used in botnets can collect information from compromised devices.

Depending on the malware, that could include credentials, financial information, personal information, or other sensitive data.

Send spam and phishing messages

Compromised devices can be used to send large volumes of unwanted messages, including phishing emails designed to compromise additional victims.

Provide access to other criminals

Botnet infrastructure can also support other cybercrime. Criminals may use compromised devices or botnet services to facilitate fraud, credential attacks, malware distribution, or other activities.

Why are IoT devices a botnet concern?

The growing number of connected devices creates more opportunities for attackers to find vulnerable systems.

Businesses may have dozens, hundreds, or thousands of connected devices across offices, facilities, and remote locations.

These might include:

  • Routers and network equipment
  • Security cameras
  • Printers
  • Smart building systems
  • Industrial equipment
  • Sensors
  • Voice or conference devices
  • Other connected appliances

NIST's IoT cybersecurity guidance identifies capabilities such as secure configuration, access control, software updates, data protection, cybersecurity state awareness, and device security as important considerations when securing connected devices.

The challenge is that organizations don't always have the same visibility or control over IoT devices that they have over employee computers.

How can you tell if a device is part of a botnet?

Botnet infections can be difficult to identify because compromised devices may continue to function normally.

Possible warning signs include:

  • Unusually slow device or network performance
  • Unexpected spikes in network traffic
  • Devices communicating with unfamiliar external systems
  • Unexpected applications or processes
  • Security alerts from endpoint or network protection tools
  • Unexplained account activity
  • Repeated connection attempts to suspicious destinations
  • Devices restarting or behaving unexpectedly

These symptoms don't necessarily mean a device is part of a botnet. They can have many other causes.

If you suspect a device has been compromised, contact your IT or security team rather than trying to investigate or remove malware on your own.

7 ways to help protect your business from botnets

There is no single security tool that can prevent every botnet infection. A layered approach can reduce the opportunities attackers have to compromise devices.

1. Keep software and firmware updated

Security vulnerabilities can provide attackers with a way into connected devices.

Install operating system, application, firmware, and security updates promptly. Pay particular attention to routers, network equipment, IoT devices, and other equipment that may not be included in your normal PC update process.

2. Replace unsupported devices

When a manufacturer stops providing security updates for a device, known vulnerabilities may remain unpatched.

The FBI has specifically warned about cybercriminals exploiting end-of-life routers that no longer receive security updates.

Maintain an inventory of connected equipment and establish a plan for replacing devices that are no longer supported.

3. Use strong authentication

Change default passwords and use strong, unique credentials for devices and services.

Enable multi-factor authentication where it is supported, particularly for administrative accounts and services that provide remote access.

4. Limit device access

Don't expose device management interfaces to the internet unless there is a specific business need and appropriate security controls are in place.

Restrict administrative access to authorized users and disable unnecessary services and features.

5. Segment your network

Network segmentation can limit the potential impact of a compromised device.

For example, an organization may separate IoT devices from systems containing sensitive business information.

NIST has demonstrated how network controls can restrict an IoT device to the communications it actually needs, reducing its exposure to network-based attacks and limiting the potential harm if the device is compromised.

6. Monitor connected devices

You can't protect devices you don't know about.

Maintain an inventory of computers, network equipment, IoT devices, and other connected systems. Monitor network activity and investigate unexpected behavior.

Regular monitoring can also help organizations identify devices that have fallen out of compliance with security requirements.

7. Train employees

Employees remain an important part of your cybersecurity defenses.

Teach employees how to recognize phishing messages, suspicious downloads, unexpected attachments, and unusual login requests.

A single compromised account or device can provide an attacker with an opportunity to gain access to additional systems.

What should you do if you think a device is infected?

If you suspect a computer, router, IoT device, or other connected system has been compromised:

  1. Report it immediately to your IT or security team.
  2. Follow your organization's incident-response procedures.
  3. Isolate the affected device if instructed to do so.
  4. Reset compromised credentials using a trusted device or process.
  5. Check for additional affected devices or accounts.
  6. Apply security updates or replace the device as appropriate.
  7. Monitor the environment for additional suspicious activity.

Don't assume that removing an obvious piece of malware means the entire incident is resolved. A security team may need to determine how the device was compromised and whether other systems were affected.

Botnets are a business problem, not just a computer problem

A botnet infection can affect more than the device that was compromised.

An infected computer or IoT device can become a foothold for additional attacks, contribute to attacks against other organizations, expose sensitive information, or consume business network resources.

The best defense is a combination of visibility, secure configuration, timely updates, strong authentication, network controls, monitoring, and employee awareness.

As businesses add more connected devices, device security needs to be part of the overall cybersecurity strategy from the beginning.

Frequently Asked Questions

What is a botnet?

A botnet is a collection of internet-connected devices that have been infected with malware and placed under an attacker's control. The attacker can coordinate the devices to perform malicious activities.

Can a laptop become part of a botnet?

Yes. A laptop or desktop can become part of a botnet if malware compromises the device. Other connected equipment, including routers and IoT devices, can also be targeted.

Can IoT devices be part of a botnet?

Yes. IoT devices can become botnet targets when attackers exploit vulnerabilities, weak credentials, insecure configurations, or other weaknesses. NIST provides cybersecurity capabilities and guidance specifically for securing IoT devices.

How do I know if my device is part of a botnet?

Botnet infections may not be obvious. Unusual network traffic, unexplained performance problems, unexpected processes, suspicious connections, or security alerts can be warning signs. If you suspect an infection, contact your IT or security team.

Can antivirus stop a botnet?

Endpoint security and malware protection can help detect and prevent some infections, but no single security technology can address every botnet threat. Businesses should combine endpoint protection with secure configurations, software updates, access controls, network segmentation, monitoring, and employee awareness.

How can small businesses protect against botnets?

Start by maintaining an inventory of connected devices, changing default credentials, enabling multi-factor authentication where available, keeping software and firmware updated, replacing unsupported equipment, limiting network access, and monitoring for unusual activity.

Why are outdated routers a security risk?

Routers that no longer receive security updates may contain vulnerabilities that attackers can exploit. The FBI has warned that cybercriminals have used end-of-life routers as part of botnet and proxy-service activity.

Disclosure: