SOLD:/24 ARIN @ $32/IP
LEASED:/18 RIPE @ $0.45/IP
LEASED:/24 ARIN @ $32/IP/Mo
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP
LEASED:/18 RIPE @ $0.45/IP
LEASED:/24 ARIN @ $32/IP/Mo
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP
SOLD:/24 ARIN @ $32/IP

What Is a Botnet? How Compromised Hosts Turn Your IP Space Into Attack Infrastructure

StephanieStephanie
How Botnet Attack Victim

A botnet is a network of compromised computers or devices running malicious software that lets a single operator control them all remotely. Each infected machine is a “bot,” the person controlling them is the “bot herder,” and the channel through which commands are issued is called command and control (C2). Together they form a distributed platform that can be pointed at any target the operator chooses.

Botnets are usually described from the target’s perspective the site knocked offline, the accounts drained, the inbox flooded. But there is a second victim in every botnet, and it is the one this article is written for: the operator whose address space the bots are running on. When machines on your IP addresses are compromised, the attacker is not just using someone else’s computing power. They are spending your IP reputation to run their operation. Spam, scanning, and attack traffic leave your addresses, get attributed to your addresses, and produce the blocklist entries and abuse reports that follow your addresses long after the malware is cleaned off the machine.

That asymmetry is the reason botnets deserve attention from anyone responsible for public IPv4 space, not just from security teams. This article explains what botnets are and how they work, why they damage address reputation at the range level rather than the single-address level, why botnet traffic is unusually hard to attribute, how to recognise compromised hosts on your own space, and how responsibility divides when the space is leased.

What is a Botnet

A botnet is a collection of Internet-connected machines infected with malware that places them under the coordinated remote control of a single operator. The individual machines continue to function normally from their owners’ point of view, which is precisely the design goal a bot that announces itself gets cleaned.

Three terms carry the concept:

  • Bot. A single compromised device running the malicious software. It can be a server, a desktop, a router, a camera, or any other connected device with enough capability to be useful.
  • Bot herder (or bot master). The operator who controls the collection and decides what it does.
  • Command and control (C2). The communication channel through which instructions reach the bots and results return. C2 is what turns a scattered set of unrelated infections into a coordinated system — without it, they are just individually compromised machines.

Scale varies enormously. Some botnets consist of a few hundred machines; documented cases have reached hundreds of thousands or more. What makes them dangerous is not any individual bot’s capability but the aggregate: thousands of geographically dispersed machines, on thousands of different networks, acting in concert.

How Do Botnets Work?

A botnet operates in three stages: infection, control, and coordinated action.

  1. Infection. Malware reaches a device and installs itself, typically designed to persist quietly through reboots and to avoid producing symptoms the owner would notice. Modern bot malware often installs additional components over time rather than arriving as a single complete package.

  2. Control. The infected machine reaches out to command-and-control infrastructure to register itself and await instructions. This check-in behaviour — repeated, patterned contact with external infrastructure — is one of the more reliable detection signals, since it is something the machine does that its owner never asked for.

  3. Coordinated action. The operator issues instructions, and some or all of the bots act simultaneously: sending traffic at a target, transmitting spam, relaying connections, scanning address ranges, or harvesting data. The same collection can be repurposed for different activities on different days.

One structural feature matters for the rest of this article: the bots do the acting, so the traffic carries their addresses not the operator’s. The bot herder may be anywhere; what the targets and the reputation systems see is the address of a compromised machine sitting on someone’s legitimate network. That is the entire point of the architecture, and it is why the operator whose space hosts the bot absorbs the consequences.

How Devices Get Recruited

Devices join botnets through the same weaknesses that lead to any compromise and awareness of the common routes is what makes prevention practical. The recurring ones, described at the awareness level:

  • Unpatched vulnerabilities. Exploitation of known flaws in operating systems, applications, and network-facing services. Unmaintained systems are disproportionately represented in botnets for the obvious reason.
  • Weak or default credentials on exposed services. Automated attempts against Internet-facing login interfaces — SSH, RDP, admin panels, and similar succeed regularly where credentials are weak, reused, or left at defaults.
  • Phishing and malicious attachments. The classic user-facing route, delivering malware through email links and files.
  • Drive-by downloads. Malware installed through compromised or malicious websites without deliberate user action.
  • IoT and embedded devices with default settings. Cameras, routers, and similar devices shipped with default credentials and rarely updated have become a major recruitment pool, since they are numerous, always on, and seldom monitored.

This is also the right place to clear up a common confusion: brute-force attacks and botnets are not the same thing. A brute-force attack is a method systematically trying credentials until one works. A botnet is infrastructure a network of compromised machines. They intersect because botnets are frequently used to carry out distributed credential attacks (spreading attempts across many bots so no single source looks abnormal), and because successful credential guessing is one way machines get recruited into botnets. But neither requires the other.

What Botnets Are Used For

Botnets are general-purpose attack infrastructure, which is why the same collection can be rented out for entirely different purposes. The main uses:

  • DDoS attacks. The best-known application: thousands of bots directing traffic at one target simultaneously. The distributed nature is what makes these attacks difficult to filter by source, and it shapes the defences described in our guide to DDoS mitigation.
  • Spam distribution. Sending unsolicited email from many compromised hosts rather than from identifiable infrastructure — historically one of the highest-volume uses.
  • Credential and data theft. Harvesting passwords, financial details, and other data from infected machines.
  • Distributed credential attacks. Spreading login attempts across many bots so each source stays below detection thresholds.
  • Scanning and reconnaissance. Systematically probing address ranges to find further vulnerable hosts — both to expand the botnet and to build target lists.
  • Proxy relays. Using compromised hosts to relay the operator’s own traffic, concealing its true origin behind a legitimate machine’s address.
  • Click fraud and cryptomining. Monetising the aggregate — generating fraudulent ad traffic, or using the collective processing power of infected devices without their owners’ knowledge.

Botnets are also commercialised. Access is rented out to third parties who want attack capability without building their own infrastructure — a service model that lowers the technical barrier to launching attacks and helps explain why botnet activity persists as a background constant rather than fading as defences improve.

Why Botnets Damage Your IP Reputation

Botnet activity from your address space is attributed to your address space and the resulting reputation damage typically affects a range, not just the individual infected address. This is the cost that lands on the operator rather than the target, and it outlasts the infection.

The mechanism has three parts:

First, attribution follows the address. When a bot sends spam or attacks a target, the recipient sees a source IP address belonging to your space. Blocklist operators, reputation systems, and mail providers record it against that address, and abuse reports are directed to the abuse contact registered for the block a process covered in detail in our guide to network abuse and handling abuse reports. Nothing in this chain identifies the actual operator; the address is what gets recorded.

Second, evasion tactics spread the damage across ranges. Botnet operators deliberately keep per-host activity low to stay under detection thresholds — sending a smaller volume of spam from each of a larger number of compromised hosts, rather than a high volume from a few. Research on spam-emitting botnets documents exactly this shift: reducing volume per compromised host specifically to evade anti-spam detection. The consequence for operators is that botnet abuse tends to touch many addresses lightly rather than one address heavily, which is how a single compromise event can degrade the standing of a whole neighbourhood of addresses — including ones that were never infected.

Third, reputation recovers slowly. Cleaning the infected machine stops the emission but does not clear the record. Blocklist entries require delisting, reputation scores rebuild over time, and mail deliverability from affected addresses can remain impaired well after remediation — the dynamics described in our guide to IP address reputation.

The practical framing: a compromised host is a security incident measured in hours, while the reputation damage it causes is measured in weeks or months, on an asset every service you run depends on.

Why Botnet Traffic Is Hard to Attribute

Several properties of modern addressing make botnet activity unusually difficult to trace back to specific machines which complicates both defence and dispute.

Dynamic address churn. Infected hosts on consumer connections change addresses constantly as ISPs reassign them. The landmark academic analysis of the Torpig botnet found this effect so pronounced that infected hosts appeared with a new address almost every time they connected, with one host observed changing addresses 694 times in ten days — and the same machine appearing across different /16 subnets within the same autonomous system. The consequence is that address-based counting massively overstates botnet size, and that “the address that misbehaved yesterday” may belong to an entirely different subscriber today.

Shared addresses. Where carriers place many subscribers behind one public address the CGNAT arrangement most mobile and many broadband providers use a single infected device causes the shared address to be flagged, affecting every legitimate user behind it. Attribution to a specific machine is impossible from outside.

Deliberate origin concealment. Bots are used as relays precisely so the operator’s own traffic appears to come from a compromised host. Separately, attackers may forge source addresses entirely, as described in our guide to IP spoofing in which case your addresses can appear in attack traffic that never touched your network at all.

For an operator, the implication is that being flagged is not proof of local compromise, and being clean is not proof of innocence in the eyes of a reputation system. Both directions require evidence — which is why retaining traffic records matters as much for defending your space as for investigating it.

Signs Your Network Hosts Compromised Machines

 Compromised hosts announce themselves through outbound behaviour, not through anything visible on the machine itself. The signals worth watching:

  • Unexplained outbound traffic volume. Sustained outbound activity that does not match the system’s function — particularly from servers with predictable normal patterns.
  • Unexpected mail volume. Outbound SMTP from hosts that should not be sending mail, or a jump in volume from those that should.
  • Outbound scanning. Your addresses probing wide ranges of external hosts — a strong indicator of either compromise or misuse.
  • Repeated patterned contact with unfamiliar external infrastructure. The check-in behaviour of C2 communication tends to be regular and machine-like in a way ordinary traffic is not.
  • Abuse reports. Often the first notification an operator receives, which is why a monitored, working abuse contact is a detection mechanism as much as an administrative obligation.
  • Blocklist appearances. Discovering your addresses listed, especially without an obvious cause, warrants investigating for compromise rather than assuming an error.
  • Resource anomalies. Unexplained CPU load can indicate cryptomining components, which are among the more detectable payloads for exactly this reason.

The common thread is that detection comes from watching what leaves your network. Inbound monitoring tells you about attempts against you; outbound monitoring tells you whether you have become part of someone else’s operation.

Botnets and Leased IPv4: Shared Responsibility

Botnet compromise is the most common real-world trigger of the coordination problem inherent in leased address space: reports arrive at the holder, while only the user can clean the machine.

The division is structural. The lessee controls the systems, so they are the only party who can isolate and remediate an infected host. The holder’s abuse contact is what appears in registry records, so they are the party who receives the reports — and whose block’s reputation is being spent while the issue goes unresolved. Neither can complete the response alone.

What each side owes, in practice:

  • The lessee secures their systems, monitors outbound traffic, acts promptly on forwarded reports, and recognises that the reputation being damaged is a shared asset attached to addresses they will keep using.
  • The holder or lessor maintains a monitored abuse contact, relays reports quickly and clearly, monitors the reputation of the space, and escalates where remediation does not happen.

This is why abuse and compromise handling belongs on the pre-lease verification list alongside routing authorization and reverse DNS. The questions are concrete: who receives abuse reports, how fast are they relayed and through what channel, who is expected to respond, what are the escalation terms if abuse continues, and will the lessor assist with delisting afterward? A structured arrangement the standard a IPv4 leasing platform should meet defines these in writing. An informal one leaves the lessee unaware of reports they never see while the block degrades. The same diligence applies when you Buy IPv4 addresses: a block’s history of botnet-related abuse is part of the reputation you inherit.

Preventing Your Systems From Joining a Botnet

The measures that keep systems out of botnets are unglamorous and well established:

  • Patch promptly. Known, unpatched vulnerabilities in Internet-facing services are the most consistently exploited route.
  • Eliminate weak and default credentials. Especially on anything exposed to the Internet, and especially on embedded and IoT devices where defaults often survive deployment.
  • Restrict exposed management interfaces. SSH, RDP, and admin panels should not be openly reachable from the entire Internet where an allowlist, VPN, or bastion arrangement is possible.
  • Filter outbound source addresses. Ensuring traffic leaving your network carries only addresses you legitimately hold prevents a compromised host from emitting spoofed traffic in your name.
  • Apply outbound rate limits. Limits on outbound mail and connection rates turn a catastrophic compromise into a contained one by capping how much damage a bot can do before detection.
  • Monitor outbound traffic. The single highest-value practice, because it is how you find compromise before the reports arrive.
  • Audit exposed services. Know what is reachable from the Internet on your space, and close what does not need to be.

Practical Checklist

  1. Monitor outbound traffic for volume anomalies, unexpected mail, and scanning from your space.
  2. Keep Internet-facing systems patched, with a defined process rather than ad-hoc updates.
  3. Eliminate default and weak credentials, particularly on exposed and embedded devices.
  4. Restrict management interfaces rather than exposing them to the open Internet.
  5. Implement outbound source-address filtering and outbound rate limits.
  6. Maintain a monitored abuse contact — it is often your first compromise notification.
  7. Monitor the reputation of your address space, including ranges not currently in heavy use.
  8. Retain traffic records sufficient to establish what did and did not originate from your network.
  9. Have a defined response: isolate, remediate, find the entry point, answer reports, pursue delisting.
  10. For leased space, confirm in writing how abuse reports are relayed and who responds.
  11. After any incident, check surrounding addresses for reputation impact and further compromise.

Final Thoughts

A botnet is a network of compromised machines under one operator’s remote control, coordinated through command-and-control infrastructure and used for DDoS attacks, spam, credential theft, scanning, proxying, fraud, and mining — often rented out to others who want attack capability without building it. Devices are recruited through unpatched vulnerabilities, weak credentials on exposed services, phishing, drive-by downloads, and unmaintained IoT defaults, and the malware is designed to persist without giving the owner any obvious sign.

For anyone operating public IPv4 space, the important shift in perspective is that a botnet has two victims: the target it attacks and the network whose addresses it attacks from. Botnet traffic carries your addresses, so it accrues to your reputation — and because operators deliberately spread activity thinly across many hosts to evade detection, the damage tends to reach whole ranges rather than single addresses, while dynamic address churn and shared carrier addresses make precise attribution genuinely difficult. The defences follow from that: watch outbound traffic, keep exposed systems patched and credentialed properly, filter and rate-limit what leaves your network, keep a monitored abuse contact, and respond fast when something does slip through. Do that, and a compromise stays an incident. Neglect it, and it becomes a lasting cost carried by the address space every one of your services depends on.

Frequently Asked Questions

What is a Botnet in simple terms?

A botnet is a group of computers or devices infected with malware that lets one attacker control them all at once. The owners usually have no idea, and the attacker uses the combined machines to send spam, launch attacks, steal data, or relay traffic.

What is a bot herder?

A bot herder, also called a bot master, is the person or group controlling a botnet. They issue instructions to the infected machines through command-and-control infrastructure and decide what the botnet is used for — or rent that capability out to others.

Are botnets and brute-force attacks the same thing?

No. A brute-force attack is a method — systematically trying credentials until one works. A botnet is infrastructure — a network of compromised machines. They overlap because botnets are often used to run distributed credential attacks, and because successful credential guessing is one way machines get recruited into botnets, but neither requires the other..

What are botnets used for?

DDoS attacks, spam distribution, credential and data theft, distributed login attacks, scanning for further vulnerable hosts, relaying traffic to conceal the attacker’s origin, click fraud, and cryptomining. Access to botnets is also commonly rented out to other criminals.

Does botnet activity affect my IP reputation?

Significantly. Traffic from compromised hosts is attributed to your addresses, producing blocklist entries and abuse reports. Because operators spread activity thinly across many hosts to evade detection, the damage often affects surrounding addresses too, and reputation recovers far more slowly than the infection takes to clean.

Can leased IP addresses be affected by botnet activity?

Yes, and it creates a coordination problem: abuse reports reach the registered holder’s abuse contact, while only the lessee can isolate and clean the infected machine. The lease should define how reports are relayed, who responds, escalation terms, and whether the lessor assists with delisting.

How do I recover IP reputation after botnet abuse?

Fix the underlying compromise first, since delisting generally requires demonstrating the issue is resolved. Then respond to any outstanding abuse reports, work through the removal processes of the blocklists involved, check surrounding addresses for impact, and allow time reputation rebuilds gradually rather than immediately.