Botnets: when devices become zombies

Table of Contents
Through botnets, malicious actors can take control of corporate or personal devices and launch DDoS or social engineering campaigns against businesses
Can a router, a computer or a camera be turned into ‘zombies’ that attack businesses, institutions and members of the public around the world? That is precisely what a botnet – or, in other words, a network of bots – achieves.
Botnets have become a major threat to companies and public authorities. Consequently, efforts to combat them and protect organisations from attacks launched through them have stepped up.
Just a few days ago, it was revealed that a botnet called Dysphoria had managed to compromise 200,000 devices worldwide and had used them to launch distributed denial-of-service (DDoS) attacks.
Meanwhile, in the spring, the United States and Canada arrested the operator of one of the world’s most dangerous botnets, KimWolf, which had been used to launch DDoS attacks against thousands of organisations, including the US Department of Defense.
Below, we will explain what a botnet is, what it is used for, and how a company or institution can protect itself against attacks launched via a botnet.
What is a botnet and how does it work?
A malicious actor exploits vulnerabilities in internet-connected devices such as computers, routers, and IoT devices – which are widely used in businesses and homes – to gain access to them and infect them with malware. This enables the malicious actor to control them remotely.
By utilising thousands of devices under their control, a malicious actor can launch large-scale attacks without needing to invest in setting up an expensive technological infrastructure.
Thus, the malicious actor managing the botnet controls the ‘zombie’ devices via remote commands from a command-and-control (C2) server, which communicates with the devices using encryption protocols and algorithms to remain undetected, or via a decentralised network in which the infected devices communicate with one another to relay the malicious actor’s commands.
Over the years, cybercriminals have refined and sophisticated the way a botnet operates to make it harder to detect and dismantle. In fact, in the case of Dysphoria, it was found that blockchain technology and repeaters were used on the infected devices to conceal the C2 servers and hinder the response to attacks launched from this botnet.
In this way, it is possible to automatically get numerous devices to carry out the same action – for example, using hundreds of computers to send out mass phishing campaigns. As a result, the devices in the botnet effectively act as a horde of zombies controlled, in this case, by the malicious actor who managed to infect them.
How are the devices that make up a botnet infected?
The infection of devices is an essential element of any botnet. If malicious actors fail to turn computers, mobiles, routers, or IoT devices into ‘zombies’, they cannot operate. How do they gain access to them and infect them with malware? Through:
- Social engineering: in the case of computers and mobile phones, it is common for social engineering techniques to be used to trick victims into installing malware on their devices without realising it, for example, by downloading an infected mobile app or clicking on a fake website.
- Weak Telnet or SSH credentials, protocols that allow remote connection to devices.
- Known vulnerabilities for which security patches already exist, but which have not been installed on the devices. For example, Dysphoria exploited vulnerabilities such as React2Shell, whilst the C0XMO IoT botnet spread by exploiting a vulnerability present in the firmware of DD-WRT routers.
- Vulnerabilities in devices that have reached the end of their life cycle (EoL). In June 2026, the AryStinger botnet managed to take control of thousands of obsolete routers that no longer receive security updates, thanks to the Dropbear SSH backdoor and DNS manipulation.

What do cybercriminals use a botnet for?
Controlling an infrastructure comprising thousands of devices allows malicious actors to:
- Launch mass social engineering campaigns targeting a wide range of potential victims, with the aim of also taking control of their devices, stealing software access credentials, or carrying out digital fraud.
- Steal data from the businesses and individuals who own the infected devices. By taking control of the devices, malicious actors gain access to highly valuable information about businesses and individuals.
- Launching DDoS attacks to disrupt the services of businesses and institutions. The botnet acts in a coordinated manner to overwhelm system resources and block access to them by legitimate users. Some malicious actors extort organisations into paying to stop the DDoS attacks, exploiting the importance of the targeted systems to the victims. Others simply seek to cause harm to companies and public authorities.
- Carrying out brute-force attacks to crack the passwords of devices and software and gain access to them.
- Carrying out cryptocurrency mining. For example, the BitcoinMiner malware infects devices and uses them unlawfully to mine cryptocurrencies and generate revenue.
- Proxying malicious traffic, using the IP addresses of infected devices to conceal the addresses from which cybercriminals carry out their malicious activities and make it appear as though the attacks originate from their victims’ homes or premises. For example, in May 2026, the Dutch government dismantled a botnet that had managed to infect 17 million devices to launch DDoS attacks, mine cryptocurrencies, and proxy malicious traffic. And a few months earlier, in March, the FBI had publicly warned about the proliferation of residential proxy networks used to obfuscate criminal activities.
Given the ways in which cybercriminals utilise a botnet, it is clear that their primary objective is to monetise their malicious activity by generating illicit revenue.
The commercialisation of botnets through Cybercrime-as-a-Service models
Precisely for this reason, it should come as no surprise that the criminal groups behind botnets do not merely use them for their own malicious activities, but instead implement Cybercrime-as-a-Service models to commercialise their use by other attackers.
For example, the KimWolf botnet was monetised through a DDoS-as-a-Service model, in which malicious actors lacking sufficient resources or expertise could use the botnet’s zombie devices to carry out attacks in exchange for a subscription fee or a percentage of the profits made.
The scale of this type of criminal model is such that, when the arrest of the malicious actor managing KimWolf was announced, it was also revealed that lawsuits had been filed in California to dismantle 45 DDoS-as-a-Service platforms.
Similarly, botnets can also be linked to other criminal models such as Phishing-as-a-Service.
This means that more malicious actors can exploit botnets comprising thousands of computers, mobile phones, routers or IoT devices to carry out attacks against citizens, businesses and public institutions.
Can AI be used to operate a botnet?
Whilst the convergence of botnets and Cybercrime-as-a-Service models represents a worrying trend, the role that Artificial Intelligence may play in managing a botnet is no less concerning.
Recently, an investigation revealed that a threat actor known as bandcampro was using Gemini CLI AI to operate a small botnet comprising eight systems at a dental clinic.
The AI agent had responded effectively to all the malicious actor’s prompts, resolved issues during the operation, and proposed operational improvements to refine the botnet’s performance.
This case demonstrates that cybercriminals can misuse AI tools to set up and manage a botnet, and implement changes to optimise it and make it more difficult to detect and stop.

How can businesses prevent and detect attacks on their devices?
One of the most important issues surrounding a botnet is that malicious actions harm both the owners of the devices – which are turned into ‘zombies’ at the service of criminals – and the members of the public or organisations targeted by the attacks carried out via these devices.
For this reason, companies and public authorities must not only prevent attacks carried out via a botnet, but also prevent their own devices from being turned into part of a botnet.
How can attempted attacks against corporate devices be detected and prevented? Through:
- Continuous monitoring of their IT infrastructure, combining automated tools for detecting malicious activity with the expertise of specialist professionals.
- Regular security audits of IoT devices and other equipment to detect vulnerabilities in devices that could leave them open to infection.
- Social engineering tests, aimed at training staff and preventing them from carrying out actions that could facilitate the infection of devices with malware.
- Advanced penetration tests to check whether malicious actors can incorporate corporate devices into a botnet, access sensitive information, or use them to carry out attacks.
- The implementation of security policies that include:
- Changing the factory settings and credentials of IoT devices to strong passwords.
- Immediately installing security updates released by manufacturers.
- Discontinuing the use of devices that have reached the end of their life cycle and for which security patches are no longer being developed.
And what about personal computers and mobile phones, or IoT devices used in the home? The security policies described above can also be implemented by members of the public.
As for detecting the unauthorised use of devices via a botnet, INCIBE highlights some tell-tale signs:
- Device performance is reduced, as they have to carry out both the actions requested by users and those ordered by malicious actors.
- The lifespan of the devices is shortened, as they are subjected to a significantly higher level of use and strain.
- Electricity consumption increases.
- The device owner may detect suspicious access to programmes or applications, or fall victim to fraud attempts carried out using information obtained from their personal devices.
How can businesses protect themselves against attacks launched via a botnet?
And what about attacks carried out using botnets? How can they be countered? In addition to conducting security audits and social engineering tests, organisations can:
- Carry out DoS tests to improve their resilience against large-scale distributed denial-of-service attacks.
- Undergo advanced penetration testing to simulate attacks carried out via a sophisticated botnet in a controlled environment, enabling them to identify improvements that help detect and respond to malicious activity.
- Utilise MDR services to:
- Carry out proactive threat detection, identifying malicious activity before it generates any tell-tale signs, so that action can be taken as swiftly and effectively as possible.
- Respond to attacks carried out using botnets from the very outset, identify the extent of the compromise, expel the malicious actor using the botnet, and ensure business continuity.
Ultimately, reality is not quite as terrifying as George A. Romero’s or Zack Snyder’s Dawn of the Dead, but the rise of botnets shows us that zombies do not only exist in films. And although a computer, a router, or a CCTV camera may not be as frightening as the living dead, they can prove to be highly effective weapons of attack in the service of cybercriminals’ nefarious interests.
It is therefore essential that organisations invest in protecting their devices and prepare themselves against attacks carried out via botnets.