What a botnet is
The word combines robot and network. Each hijacked device, often called a bot or zombie, runs a small program that waits for orders from the operator's command servers. On its own, one infected router or phone does little. Together, thousands of them give the operator something valuable: a huge pool of real, trusted internet connections spread across homes, offices and mobile carriers.
Botnets are a business. Operators rent capacity by the hour for floods, by the million for spam, or by the gigabyte as proxy traffic. Some of the cheap residential proxy supply on the market comes from devices whose owners never knowingly agreed to share their connection.
How a botnet is built and used
- 01
Infect
Malware spreads through weak default passwords on routers and cameras, unpatched software, pirated apps, or app and browser extension kits that quietly turn the device into a relay.
- 02
Connect
Each device checks in with the operator's command servers and waits. Many run for months without the owner noticing anything beyond a slower connection.
- 03
Rent out
The operator sells access: a flood against a target, a spam run, a credential list to test, or raw traffic routed through the devices as proxies.
- 04
Attack
Thousands of devices send requests at once or in slow, spread-out waves, each from a clean-looking home or mobile IP address.
How botnets show up in your traffic
The obvious case is a layer-7 flood: a surge of valid-looking page or API requests that exhausts servers. The quieter and more common case is abuse spread thin. A credential stuffing run may send only a handful of attempts per IP address, so per-IP rate limits never trigger, while the total adds up to hundreds of thousands of login tries.
Because the addresses belong to real people, blocking them outright can lock out real customers who share the same carrier or neighborhood. What gives botnet traffic away is everything around the IP: the same automation behind every request, identical device traits from supposedly different homes, and timing that no group of independent people would produce.
- Many IP addresses, few distinct real devices behind them.
- Requests that jump between countries and carriers in a pattern.
- The same script behavior, form timing or header order across every source.
- Sudden bursts that begin and end together on a command.
How to defend against botnet traffic
Treat the network as one signal, not the verdict. Kavra measures the real exit IPs of commercial residential and mobile proxy networks on top of 30+ public reputation feeds, and weighs that against device, browser integrity and behavior. It also watches for coordinated campaigns: surges of new devices, shared infrastructure and velocity anomalies across many sources. See residential proxy detection and how Kavra stops credential stuffing spread across thousands of addresses.