# What is a botnet?

Source: https://kavralab.com/glossary/botnet/

A **botnet** is a network of computers, phones, routers and other connected devices that have been taken over by malware or questionable apps and are controlled remotely by one operator. The owners usually have no idea. Botnets send floods, spam and login attacks from thousands of real addresses. Kavra judges each request on more than its IP.

## What a botnet is

The word combines robot and network. Each hijacked device, often called a bot or zombie, runs a small program that waits for orders from the operator's command servers. On its own, one infected router or phone does little. Together, thousands of them give the operator something valuable: a huge pool of real, trusted internet connections spread across homes, offices and mobile carriers.

Botnets are a business. Operators rent capacity by the hour for floods, by the million for spam, or by the gigabyte as proxy traffic. Some of the cheap [residential proxy](https://kavralab.com/glossary/residential-proxy/) supply on the market comes from devices whose owners never knowingly agreed to share their connection.

## How a botnet is built and used

1. **Infect**: Malware spreads through weak default passwords on routers and cameras, unpatched software, pirated apps, or app and browser extension kits that quietly turn the device into a relay.
2. **Connect**: Each device checks in with the operator's command servers and waits. Many run for months without the owner noticing anything beyond a slower connection.
3. **Rent out**: The operator sells access: a flood against a target, a spam run, a credential list to test, or raw traffic routed through the devices as proxies.
4. **Attack**: Thousands of devices send requests at once or in slow, spread-out waves, each from a clean-looking home or mobile IP address.

## How botnets show up in your traffic

The obvious case is a layer-7 flood: a surge of valid-looking page or API requests that exhausts servers. The quieter and more common case is abuse spread thin. A [credential stuffing](https://kavralab.com/glossary/credential-stuffing/) run may send only a handful of attempts per IP address, so per-IP rate limits never trigger, while the total adds up to hundreds of thousands of login tries.

Because the addresses belong to real people, blocking them outright can lock out real customers who share the same carrier or neighborhood. What gives botnet traffic away is everything around the IP: the same automation behind every request, identical device traits from supposedly different homes, and timing that no group of independent people would produce.

- Many IP addresses, few distinct real devices behind them.
- Requests that jump between countries and carriers in a pattern.
- The same script behavior, form timing or header order across every source.
- Sudden bursts that begin and end together on a command.

## How to defend against botnet traffic

Treat the network as one signal, not the verdict. Kavra measures the real exit IPs of commercial residential and mobile proxy networks on top of 30+ public reputation feeds, and weighs that against device, browser integrity and behavior. It also watches for coordinated campaigns: surges of new devices, shared infrastructure and velocity anomalies across many sources. See [residential proxy detection](https://kavralab.com/detect/residential-proxies/) and how Kavra stops [credential stuffing](https://kavralab.com/solutions/credential-stuffing/) spread across thousands of addresses.

## FAQ

### How do I know if my device is part of a botnet?

Signs include an unusually slow connection, high data use when idle, a router or camera still on its default password, unknown apps or browser extensions, and your IP address suddenly hitting CAPTCHAs or blocks on sites you use. Update firmware, change default passwords, remove unknown apps and run a reputable security scan.

### Why do botnets use home and mobile IP addresses?

Because websites trust them. Data center addresses are easy to flag, while home broadband and mobile carrier addresses are shared with real customers, so blocking them causes collateral damage. A botnet gives attackers thousands of these trusted addresses at once, which defeats simple IP blocklists and per-IP rate limits.

### What is the difference between a botnet and a DDoS attack?

A botnet is the tool; a DDoS attack is one way to use it. A distributed denial-of-service attack floods a target from many sources at once, and botnets are the usual source. The same botnet can also run spam campaigns, login attacks, click fraud or proxy services when it is not flooding anyone.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
