A botnet is a collection of internet-connected devices that have been compromised by malware and placed under the control of a threat actor — known as a botmaster or operator. Each infected device, referred to as a bot or zombie, receives instructions from a command-and-control (C2) infrastructure and executes them without the knowledge of the device owner.
Botnets are used to conduct a range of malicious activities at scale — including distributed denial-of-service (DDoS) attacks, spam and phishing campaigns, credential stuffing, cryptomining, and malware distribution.
The value of a botnet lies in its scale and distribution. A single attacker controlling thousands or millions of devices can generate traffic volumes, attack breadth, and geographic diversity that would be impossible to achieve from a single source — and far harder to block.


