Skip to main content
FixMyTech

What Is a Botnet and How Devices End Up in One

By

Published

8 min read

Share

Short answer

A botnet is a collection of compromised devices — computers, routers, cameras, smart plugs — that quietly take instructions from one operator. Most consumer devices join through a default or reused password on something internet-facing, not through a clever exploit. Changing default passwords and keeping router firmware updated removes nearly all of the realistic risk.

On this page

A botnet is a large number of devices that have been quietly compromised and now take orders from a single operator. The individual owners have no idea. That is the design: a botnet that announces itself gets cleaned up, so the malware is written to use as little of your bandwidth and processing power as it can get away with.

The devices are not all computers. In practice the bulk of a modern botnet is routers, security cameras, digital video recorders, smart plugs and other hardware that was sold cheaply, shipped with a default password, and has not received a firmware update since the manufacturer lost interest.

What the operator actually wants

Nothing personal. Your files are not the target and your photographs are of no interest. A botnet wants three resources, all of which you own and none of which you monitor.

Bandwidth, for sending traffic at a target until it falls over. An IP address that belongs to a residential customer rather than a data centre, which makes traffic look legitimate — this is why compromised home connections get resold as proxies for ad fraud and credential stuffing. Processing time, for mining cryptocurrency or working through stolen password lists.

None of that requires touching your documents, and touching them would risk you noticing. The economics push firmly towards staying invisible.

How a device joins

Entry route Typical device How common
Default or weak admin password Router, camera, DVR The large majority
Unpatched firmware flaw Router, NAS, IoT hardware Common
Pirated software or cracked installer Windows PC Common
App installed from outside the official store Android phone Occasional
Exposed remote access left on Router, home server Occasional

The first row is the one people underestimate. An enormous share of device compromise happens because the device shipped with admin/admin, was connected to the internet, and was found by automated scanning within hours. There is no sophistication involved. Entire address ranges are swept continuously by automated systems, and anything answering with a known default is added.

Windows machines generally join by a different route: software the owner installed deliberately. Cracked applications, “free” versions of paid software and key generators are an efficient delivery mechanism, because the user has already decided to ignore the security warning and frequently disables the antivirus to make the thing run at all.

Phones are the least affected. iOS does not permit the kind of background persistence a botnet needs, and Android phones that only install from the Play Store are in reasonable shape. Sideloaded applications from forums and third-party stores are where the risk concentrates, and the signs of actual phone malware covers how to tell real infection from the much more common false alarm.

Signs worth taking seriously

Most “symptoms” people attribute to botnets are something else entirely. Slow internet is almost always Wi-Fi, congestion or the provider. A hot laptop is usually a browser tab. The signals below are the ones with few innocent explanations.

Your provider sends an abuse notice. Internet providers receive reports when a customer’s address attacks someone else, and they forward them. This is the single most reliable indicator, and it is worth acting on rather than ignoring.

Sites start challenging you constantly. Persistent captcha prompts, blocked checkouts, or services refusing your address suggest your IP has a reputation problem. Shared addresses can cause this innocently, but it is worth a look.

Your router is busy when nothing is using it. Unplug or power down every device in the house, then watch the router’s activity lights. Steady traffic with nothing connected is abnormal. Check the DHCP client list in the admin pages while you are there, and account for every device on it.

Router settings change on their own. Specifically the DNS servers. Malware that alters a router’s DNS settings redirects every device in the house without touching any of them, and it is one of the more damaging things in this category. Write down what your DNS entries should be and check them occasionally.

A desktop machine holds high CPU with nothing open. Cryptocurrency mining is the usual explanation when it is real, although a scheduled antivirus scan explains it far more often — Antimalware Service Executable using high CPU covers that case, and finding what is using 100% CPU identifies the process either way.

The checks that remove most of the risk

Ninety percent of the realistic exposure comes down to a short list, and the router is where most of it sits.

Change the router’s admin password. Not the Wi-Fi password, which is a different thing — the password for the router’s own settings pages. The default is printed on a sticker and on the internet. While you are there, confirm the Wi-Fi uses WPA2 or WPA3 rather than the older options.

Update the router’s firmware. Log in to the admin pages and look for a firmware or update section. Routers more than about five years old frequently receive no updates at all, and a router that the manufacturer has stopped supporting is a reasonable thing to replace. It is the single most exposed device you own and it runs continuously.

Turn off remote administration. Also called remote management or web access from WAN. Unless you specifically need to configure your router from outside the house, it should be off. This one setting accounts for a great deal of router compromise.

Turn off UPnP if you can live without it. It lets devices open ports through the firewall automatically, which is convenient for games and consoles and is also a route to exposing things you did not intend. Try disabling it and see what breaks.

Change default passwords on cameras and smart devices. Anything with a login and an internet connection. If a device cannot have its password changed, it should not be reachable from outside your network at all.

Stop installing cracked software. Unglamorous advice, consistently ignored, and responsible for a large share of consumer compromise.

If you think a device is already compromised

Routers first, because they affect everything else. Factory reset the router using the physical reset button, then set it up again from scratch with a new admin password and updated firmware. Much router malware lives only in memory and does not survive this. Do not restore a saved configuration backup, since the problem may be in it.

For a Windows PC, run an offline scan rather than a normal one, because malware already running can interfere with a live scan. The procedure is in scanning for and removing malware on Windows.

For a cheap camera or smart device with no firmware updates available, the honest answer is that it should be disconnected and replaced. There is no cleaning process for hardware the manufacturer abandoned.

Realistic expectations

If you are running a current Windows or macOS machine with its built-in protection enabled, installing software from legitimate sources, and your router is from the last few years with a changed admin password, the likelihood that you are part of a botnet is low.

The risk concentrates almost entirely in two places: devices nobody has logged into since the day they were installed, and software obtained from places that required disabling the antivirus. An afternoon spent changing router credentials and updating firmware is worth more than any security product you could buy, and unlike the product it does not need renewing every year.

Frequently asked questions

How would I know if my device is in a botnet?
Usually you would not, because being quiet is the point. The practical signals are indirect — your internet provider sending an abuse notice, your IP address being blocked by sites, or a router running hot and slow with no one using it.
Can a phone be part of a botnet?
It is possible but uncommon on iPhones and on Android phones that only install from the Play Store. The realistic route is an app sideloaded from outside the official store, which is why that one habit matters more than any security app.
Does a botnet steal my files?
Usually not, because that is not what it is for. A botnet wants bandwidth, an IP address and processing time, so file theft would draw attention for little gain. Different malware does that job.
Why would anyone want my old router?
Because it is always on, rarely updated, and nobody looks at it. A single home router is worthless; a hundred thousand of them are a service that can be rented out, and that is the business model.
Does resetting a router remove the infection?
Often yes, since much router malware lives in memory and does not survive a power cycle or a factory reset. Reset, then update the firmware and change the admin password before reconnecting, otherwise the same route back in is still open.

All Security guides