Botnet Groups | How Mirai, Emotet, QakBot, Aisuru and Other Botnets Work (and How to Detect and Stop Them)

Botnet groups are networks of hacked devices run by criminal operators, who use them to steal data, spread ransomware, and launch DDoS attacks. Each group works differently. Emotet, QakBot and TrickBot mainly deliver other malware, while Mirai and Aisuru turn IoT devices into DDoS weapons.
The scale is what makes them dangerous. At its peak, Mirai controlled an estimated 600,000 poorly secured IoT devices, enough to knock major sites offline during the 2016 Dyn attack. Law enforcement has since taken down several families, including Emotet and QakBot. Operators often rebuild with new loaders and infrastructure, as Emotet and DanaBot did, so a takedown rarely ends the threat for good.
This guide covers how each major botnet spreads and communicates, which families lead to ransomware, and how to detect and stop an infection.
What Are Botnet Groups? A Quick Definition
Botnet groups are the criminal operations that build, control, and profit from networks of hijacked computers and devices. The term covers both the botnet itself, such as Mirai or Emotet, and the people behind it, who run the infrastructure and sell access to it. Each group tends to specialize. Some focus on delivering other malware, some on DDoS attacks, and some on banking fraud or spam. Knowing which one you are dealing with tells you what the infection is likely to do next.
How a Botnet Works: Infection, C2 and Monetization
A botnet works in three stages. Malware infects a device, the device connects to a command-and-control (C2) server for instructions, and the operators then turn that access into money. Infection usually comes through phishing emails with malicious attachments, exploited software vulnerabilities, or default passwords on exposed devices like routers and cameras. Once infected, devices check in with C2 servers or, in some designs, with each other through peer-to-peer connections. Some botnets generate thousands of domain names a day to make shutdowns harder, as Conficker did. Operators then rent out the access, steal banking credentials, send spam, launch DDoS attacks, or hand victims off to ransomware affiliates. Scale is the draw. When the FBI disrupted QakBot in 2023, it reported that the botnet had infected more than 700,000 computers.
Botnet vs. Malware Loader vs. Worm
A botnet is a network of compromised devices controlled centrally. A malware loader installs other malware, and a worm spreads itself without human action. The three overlap, which is why families get filed under more than one label. Emotet began as a banking trojan, grew into a loader, and eventually became a full botnet. Conficker was a worm that formed a botnet from infected machines. Mirai scanned the internet for devices with default passwords and automatically recruited them. A loader like PikaBot or SmokeLoader is often the first piece of malware on a machine, and the botnet is what the operators build from many such infections.
Who Runs Botnets: Operators, Affiliates and Botnet-as-a-Service
Operators, often called botmasters, run botnets, build the malware, and maintain the C2 infrastructure. They increasingly sell access to others rather than using it all themselves. This model is called botnet-as-a-service. Customers can be ransomware affiliates, fraud crews, or DDoS-for-hire services, and each pays for a slice of the infected network. Emotet did this at scale, giving TrickBot and Ryuk operators access to victim networks. Affiliates carry out the final attack, while botnet operators keep earning from access. This division of labor is why taking down one operator rarely ends the activity. Customers and developers move to another family.
How Botnet Names Are Pronounced and Why They’re Named That Way
Botnet names come from three places: the operators, security researchers, and antivirus vendors. Mirai is Japanese for “future,” and its creator chose it. It is pronounced roughly “MEE-rye.” Aisuru, Japanese for “to love,” is pronounced roughly “eye-SOO-roo.” Researchers often name malware after strings, filenames, or code behaviors, as families like Mozi and Conficker got their names. QakBot is usually said “quack-bot,” and Emotet’s pronunciation varies even among analysts. Because every vendor labels malware independently, many families carry several names. QakBot is also called QBot, IcedID is also called BokBot, and BASHLITE is also called Gafgyt. When researching a botnet, check every alias to avoid missing reports.
The Major Botnet Families at a Glance
The major botnet families fall into a few types. Loader and banking-trojan botnets include Emotet, QakBot, and TrickBot. IoT DDoS botnets include Mirai and Aisuru. Conficker is a worm botnet, and ZeroAccess is a rootkit botnet. Most have been disrupted at least once, and few have truly disappeared. At times, Aisuru, Kimwolf, and their sister networks controlled more than three million devices and were linked to attacks of roughly 30 terabits per second before authorities dismantled their control infrastructure in March 2026.
Comparison Table: Type, First Seen, Primary Use, Status
This table compares the most-searched botnet families by type, first appearance, main purpose, and current condition. The “first seen” years are approximate, since researchers often date a family from its earliest public sample.
| Botnet | Type | First Seen | Primary Use | Status (2026) |
|---|---|---|---|---|
| Conficker | Worm | 2008 | Self-propagation, botnet building | Legacy; lingers on unpatched systems |
| Zeus / GameOver Zeus | Banking trojan | 2007 | Banking fraud, credential theft | Disrupted 2014; code lives on in variants |
| ZeroAccess | Rootkit | 2009 | Click fraud, cryptocurrency mining | Disrupted 2013 |
| Necurs | Spam botnet | 2012 | Spam, malware distribution | Disrupted 2020; dormant |
| SmokeLoader | Loader | 2011 | Malware delivery | Disrupted 2024 |
| BASHLITE / Gafgyt | IoT DDoS | 2014 | DDoS attacks | Persists through variants |
| Emotet | Loader / banking trojan | 2014 | Malware delivery, spam | Disrupted 2021; intermittent returns |
| QakBot | Loader / banking trojan | 2008 | Initial access, ransomware | Disrupted 2023 and again in 2025 |
| TrickBot | Banking trojan / loader | 2016 | Credential theft, ransomware staging | Disrupted; developers charged |
| Mirai | IoT DDoS | 2016 | DDoS attacks | Active through many variants |
| IcedID | Banking trojan / loader | 2017 | Initial access, ransomware | Disrupted 2024 |
| DanaBot | Banking trojan / loader | 2018 | Data theft, ransomware access | Disrupted 2025 |
| DarkGate | Loader / RAT | 2018 | Malware delivery, remote access | Active as malware-as-a-service |
| SystemBC | Proxy / backdoor | 2018 | Tunneling for ransomware operators | Disrupted 2024; infrastructure resurfaces |
| Mozi | IoT P2P | 2019 | DDoS, payload delivery | Largely dormant since 2023 |
| RapperBot | IoT DDoS | 2022 | DDoS-for-hire | Disrupted 2025 |
| Bumblebee | Loader | 2022 | Initial access, ransomware | Disrupted 2024 and 2025 |
| PikaBot | Loader | 2023 | Initial access, ransomware | Disrupted 2024 |
| Aisuru | IoT DDoS | 2024 | Record-scale DDoS | Disrupted March 2026; rebuilding |
| Kimwolf | Android DDoS / proxy | 2025 | DDoS, residential proxy abuse | Disrupted March 2026; no longer active |
Botnet Timeline: Conficker (2008) to Aisuru and Kimwolf Today
Botnet history runs from worms spreading across Windows networks to modern botnets built from millions of consumer devices. Conficker (2008) showed how a single worm could infect millions of machines. Emotet appeared in 2014 as a banking trojan and later became a malware delivery service. Mirai arrived in 2016 and proved that cheap IoT devices with default passwords could take down major internet infrastructure. Mozi followed in 2019 with a peer-to-peer design. In 2021, authorities took Emotet offline, and it returned months later. The FBI-led QakBot disruption came in 2023. Then, in May 2025, Operation Endgame dismantled nearly 300 servers and 650 domains tied to ransomware delivery. Aisuru appeared in August 2024, and its offshoot, Kimwolf, infected more than 2 million Android TV boxes in a short period. On March 19, 2026, authorities seized the infrastructure behind both, along with the related JackSkid and Mossad botnets.
Active, Disrupted or Dormant: Where Each Family Stands
Most major botnet families are now disrupted or dormant rather than fully dead. Takedowns remove servers and arrest individuals, but the code and the customers usually survive.
Disrupted but rebuilding. Aisuru is the clearest case. Four months after the takedown, known Aisuru server infrastructure had more than doubled from its pre-takedown level. Kimwolf itself is reported as no longer active, but more than 20 rival botnet families adopted its techniques. Authorities criminally charged a suspected operator on April 10, 2026. The loader families hit by Operation Endgame show the same pattern. Authorities neutralized new versions of Bumblebee, QakBot, TrickBot, and others, and DanaBot infected over 300,000 devices before authorities disrupted it. Emotet has followed a similar cycle of takedown, return, and quiet periods since 2021.
Dormant or legacy. Mozi, Necurs, ZeroAccess and Conficker no longer drive major campaigns. Conficker can still appear on forgotten, unpatched systems, making it a useful sign of poor patching.
Still active. Mirai remains the template for IoT botnets. It lives on through dozens of forks, and BASHLITE/Gafgyt variants persist alongside it. DarkGate has not faced a coordinated takedown and continues to circulate as malware-as-a-service. Treat any family marked “disrupted” as a threat that could return under a new name.
Banking Trojan and Loader Botnets
Banking trojan and loader botnets began by stealing bank credentials or sending spam and now mostly sell access to infected computers. Ransomware gangs buy that access, which makes these botnets a common first step before a ransomware attack. A single law enforcement action in May 2024 against several of them took down over 100 servers and seized more than 2,000 domains.

Emotet: The Botnet That Became an Infrastructure Provider
Emotet is a malware loader that started as a banking trojan in 2014 and grew into infrastructure that other criminals rented to deliver their own malware. Its operators infected millions of Windows machines and sold access to other malware operators. It dropped QakBot and TrickBot, which in turn deployed Ryuk and Conti ransomware. When authorities took control of the botnet in January 2021, Europol said its infrastructure included several hundred servers worldwide. Emotet returned later in 2021 and has run in intermittent bursts since.
TrickBot: From Banking Trojan to Conti’s Backbone
TrickBot is a modular trojan that appeared in 2016 as a banking trojan and became a staging platform for ransomware, especially Ryuk and Conti. Microsoft and its partners disrupted its servers in October 2020 and estimated it had infected more than a million devices since 2016. Its operators overlapped heavily with the Conti ransomware group, and TrickBot’s own activity wound down in early 2022 as Conti fractured—the US and UK sanctioned members in 2023. In 2024, German authorities were seeking seven people tied to the group that spread TrickBot.
QakBot (QBot): Cobalt Strike, OneNote Lures and the FBI Takedown
QakBot, also called QBot, began as a banking trojan around 2008 and became one of the most widely used initial-access tools for ransomware. It spread through phishing and commonly deployed Cobalt Strike to give attackers hands-on control of a network. When Microsoft started blocking macros by default, its operators switched to OneNote attachments in early 2023. The FBI-led takedown in August 2023 found more than 700,000 infected computers. In 2025, the Justice Department charged Russian national Rustam Gallyamov with leading the group behind QakBot. Authorities also neutralized new versions of QakBot during a later phase of Operation Endgame.
IcedID (BokBot): Banking Trojan Turned Initial Access Broker Tool
IcedID, also known as BokBot, is a malware family that first appeared in 2017 as a banking trojan and later became a tool for selling initial access to ransomware affiliates. Europol describes it as originally a banking trojan, now used for a range of cybercrimes, including stealing financial data. This shift is common among loaders. Many droppers began as banking trojans, then moved toward initial access and stripped out noisy features to avoid detection. Operation Endgame targeted IcedID in May 2024.
PikaBot, DarkGate and Bumblebee: The Post-QakBot Loaders
PikaBot, DarkGate and Bumblebee are loaders that filled the gap in the ransomware ecosystem after QakBot’s 2023 disruption. PikaBot is a Trojan used to gain initial access, enabling ransomware deployment, remote takeover, and data theft. Bumblebee appeared in 2022 and spreads mainly through phishing or compromised websites to run further payloads. DarkGate is sold as malware-as-a-service and spreads through phishing, including chat messages. Operation Endgame hit PikaBot and Bumblebee in 2024, and authorities later neutralized new versions of Bumblebee as well. DarkGate has not faced a comparable coordinated takedown.
SmokeLoader and DanaBot: Long-Running Loaders and Operation Endgame
SmokeLoader and DanaBot are two long-running loaders that Operation Endgame went after in 2024 and 2025. SmokeLoader is primarily a downloader that installs additional malware on infected systems. Criminal customers have bought it since about 2011, and German authorities suspect an eighth person leads the group behind it. DanaBot started as a banking trojan in 2018. By May 2025, it had infected over 300,000 devices and enabled fraud and ransomware damage exceeding $50 million, and US prosecutors charged 16 people tied to it.
SystemBC: The Proxy and Backdoor Behind Ransomware Attacks
SystemBC is a proxy and backdoor that hides communication between an infected machine and its attacker’s server. Europol describes it as malware that facilitates anonymous communication between an infected system and a command-and-control server. Ransomware operators use it to tunnel traffic through a victim’s network and keep access after the initial infection. It is not a banking trojan or a loader in the strict sense. It gives attackers a quiet, persistent foothold, which is why defenders often find it during ransomware investigations. Operation Endgame targeted it in May 2024.
Zeus and GameOver Zeus: The P2P Banking Botnet
Zeus is a banking trojan first seen in 2007 that stole credentials by logging keystrokes and capturing web forms. Its source code was leaked in 2011, which produced a long line of descendants. GameOver Zeus was the most advanced. It used a peer-to-peer network instead of central servers, making it much harder to shut down, and it also distributed CryptoLocker ransomware. The US Justice Department and international partners disrupted it in June 2014 and charged its alleged leader, Evgeniy Bogachev. Officials estimated the botnet caused more than $100 million in losses.
Necurs and Storm: Spam Botnets That Shaped the Field
Necurs and Storm were spam botnets that shaped how later botnets were built and sold. The Storm worm appeared in 2007, spread through emails with sensational subject lines, and was one of the first large botnets to use peer-to-peer communication. Necurs appeared around 2012 and became one of the largest spam botnets, distributing banking trojans and ransomware such as Dridex and Locky. Microsoft and partners disrupted it in March 2020 and reported that it had infected more than nine million computers. Both showed that infected machines could be rented out to send or install whatever the customer wanted, a model today’s loaders still follow.
IoT and DDoS Botnets
IoT and DDoS botnets are networks of hijacked routers, cameras, DVRs, and TV boxes that attackers use to flood websites and networks with traffic. Mirai set the template in 2016, and most families since then either descend from its code or copy its approach. The scale has grown sharply. One recent botnet, Aisuru, was tied to a record-breaking 29.7 terabits-per-second DDoS attack.

Mirai: The 2016 Dyn Attack and Why It Still Matters
Mirai is an IoT botnet that scanned the internet for devices with factory-default passwords, infected them, and used them to launch DDoS attacks. In October 2016, it flooded the DNS provider Dyn, which knocked many major sites, including Twitter, Netflix, and Reddit, offline for hours. At its peak, it controlled roughly 600,000 devices, and its first version tried only about 60 default username and password pairs to get in. Its creators were later convicted, but its source code had already leaked. That leak is why Mirai still matters. Dozens of botnets today are built from its code, so “Mirai” is better understood as a family than a single botnet.
Mirai Variants: Mozi, BASHLITE/Gafgyt, Hajime and RapperBot
Mirai variants are botnets that reuse Mirai’s code or its method of brute-forcing weak IoT credentials. BASHLITE, also called Gafgyt, predates Mirai, appearing around 2014, and shares much of its lineage. Mozi, first seen in 2019, mixed code from several earlier families and used a peer-to-peer network instead of central servers. Its activity collapsed in 2023 after an apparent kill-switch update. Hajime, from 2016, spread like Mirai but carried no attack payload and blocked the ports Mirai used, which led researchers to treat it as an oddity. Researchers disrupted RapperBot, a Mirai-based DDoS-for-hire botnet, in August 2025, and Aisuru quickly expanded to fill the gap.
Aisuru and Kimwolf: Record-Breaking DDoS Botnets
Aisuru and Kimwolf are two closely linked DDoS botnets that produced the largest attacks recorded to date. Security researchers first identified Aisuru in August 2024. Kimwolf branched off from it and quickly took control of more than 2 million non-certified Android TV boxes. It spread by exploiting weaknesses in residential proxy networks, reaching devices normally hidden behind home firewalls. Authorities say it issued more than 1.7 billion DDoS attack commands. Law enforcement seized the infrastructure behind both botnets in March 2026, but Aisuru recovered quickly. Within four months, its known server infrastructure had more than doubled compared with before the takedown.
GorillaBot, JackSkid, Mossad Botnet and Raptor Train
GorillaBot, JackSkid, the Mossad botnet and Raptor Train are smaller or specialized botnets built on the same IoT foundations. GorillaBot is a Mirai variant that, between September 4 and 27, 2024, issued over 300,000 attack commands and targeted more than 100 countries. JackSkid and the Mossad botnet came later and were inspired by Kimwolf, adopting the same weakness in residential proxy SDKs. Authorities counted about 90,000 attack commands from JackSkid and over 1,000 from Mossad. Raptor Train is different. It was a Chinese state-linked botnet, powered by a Mirai variant and built from routers, cameras, and storage devices. The FBI said it reached over 260,000 devices before disrupting it in 2024, and attackers used it to hide espionage rather than to flood targets.
Why IoT Devices Keep Getting Recruited: Default Credentials and Exposed Services
IoT devices keep getting recruited because they ship with weak or default passwords, expose remote-access services to the internet, and rarely receive security updates. Owners also rarely notice an infection, since the device keeps working normally. Mirai-style botnets exploit default Telnet and SSH logins. Kimwolf took a different route, mainly infecting Android devices with the Android Debug Bridge left open. Cheap TV boxes and cameras often have no way to patch the flaw. Practical defenses are simple: change default credentials, turn off remote management and UPnP you don’t use, keep IoT devices on a separate network, apply firmware updates, and retire devices the manufacturer no longer supports.
Worm and Rootkit Botnets
Worm and rootkit botnets use malware that either spreads on its own or hides deep inside the operating system. Conficker is the best-known worm botnet, and ZeroAccess is the best-known rootkit botnet. Neither depends on a single phishing campaign. They spread automatically, resist removal, and survive for years. Both infected millions of computers, and defenders needed the Microsoft-led, multi-company responses described below to push them back.
Conficker: The Worm That Infected Millions
Conficker is a computer worm that appeared in November 2008 and turned millions of Windows PCs into a botnet. It spread by exploiting a flaw in the Windows Server service that Microsoft patched in October 2008 under bulletin MS08-067, but many systems had not yet applied the patch. Later versions also guessed passwords on network shares and spread through infected USB drives. Estimates of the infection varied by version, but in early 2009 they ranged from almost 9 million to 15 million computers. Conficker contacted a daily set of 250 pseudorandom domains for instructions, so defenders could not block a single address. The Conficker Working Group, a coalition of security companies and researchers, answered by sinkholing those domains before the attackers could register them. This kept the botnet from doing real harm, but the infected machines were never cleaned. The group’s chairman called it a complete success, even as the patient died.
ZeroAccess: Rootkit and Click-Fraud Botnet
ZeroAccess, also called Sirefef, is a rootkit botnet that hid on infected Windows PCs and used them to commit click fraud and hijack search results. A rootkit buries itself deep in the system, which makes it hard for antivirus tools to find and remove. ZeroAccess also mined bitcoin on some infected machines. Microsoft said the botnet had infected more than 2 million computers and cost online advertisers an estimated $2.7 million each month. Researchers at the University of California, San Diego counted 1.9 million infected computers as of October 2013, with more than 800,000 active on a typical day. The botnet used a peer-to-peer design, so infected machines passed instructions to each other instead of relying on a central server. In December 2013, Microsoft, the FBI, and Europol disrupted it by seizing control of 49 domains and blocking communication with a small number of key addresses. Microsoft said it did not expect to eliminate the botnet because of its complexity.
From Botnet to Ransomware: How Loaders Feed Ransomware Gangs
Loaders feed ransomware gangs by gaining an initial foothold in a victim’s network and then handing that access to the group that deploys the ransomware. The loader operators rarely encrypt anything themselves. They sell or pass on the access, and ransomware affiliates finish the job. As of May 2024, Black Basta affiliates alone had impacted over 500 organizations, and some of those attacks started with a loader.

Emotet, TrickBot and Ryuk: The Classic Chain
The classic botnet-to-ransomware chain runs from Emotet to TrickBot to Ryuk. Emotet arrived through a phishing email and infected the machine. It then dropped QakBot and TrickBot payloads, which in turn deployed Ryuk and Conti ransomware. TrickBot served as the middle step: stealing credentials, mapping the network, and moving laterally until the attackers controlled domain administrator accounts. Ryuk, which appeared in 2018, then launched across the network, often targeting hospitals, municipalities, and other organizations that could not afford downtime. Each family specialized in one stage. That division of labor is why defenders treated an Emotet or TrickBot alert as a ransomware warning rather than a minor malware event.
QakBot, IcedID and DarkGate Into Black Basta and Conti
QakBot, IcedID, and DarkGate are loaders that ransomware groups such as Black Basta and Conti have used for initial access. According to the CISA advisory, Black Basta affiliates primarily use spearphishing to gain initial access and have also used QakBot. IcedID served a similar role for Conti, which also drew on TrickBot. After QakBot’s 2023 disruption, researchers reported that Black Basta shifted toward other loaders, including DarkGate. The pattern shows how interchangeable loaders are. When one is taken down, ransomware affiliates switch to another access source, and the attack that follows looks much the same; only the first-stage malware changes.
Why Botnet Infections Are Early Warning Signs of Ransomware
A botnet or loader infection is an early warning sign because ransomware is usually the last step of an attack that began days or weeks earlier. Between the initial infection and encryption, the attackers need time to work. The CISA advisory describes affiliates using credential-scraping tools like Mimikatz and using RClone to exfiltrate data before encryption. Each step gives defenders a chance to detect and stop the attack. Europol framed Operation Endgame in the same terms, saying that disrupting these services breaks the kill chain at its source. A practical response to any loader alert is to treat it as a possible ransomware incident. Isolate the affected machine, reset the credentials used on it, look for remote access tools and Cobalt Strike beacons, and check for lateral movement before assuming the infection was contained.
How Botnets Are Taken Down
Authorities take down botnets by seizing their command-and-control servers and domains, cutting infected devices off from their operators, and then pursuing the people behind them with charges and sanctions. Disruption is rarely permanent, but it can be costly for criminals. One phase of Operation Endgame in 2025 dismantled nearly 300 servers and 650 domains tied to ransomware delivery.
Operation Endgame, the QakBot Takedown and Emotet’s Disruption
Operation Endgame, the QakBot takedown, and the Emotet disruption are the three largest botnet takedowns of the past five years. In January 2021, agencies from eight countries took control of Emotet. Europol said its infrastructure included several hundred servers worldwide. Investigators then pushed an update that was set to remove remaining infections on March 25, 2021. In August 2023, the FBI used a similar approach against QakBot, took over its infrastructure, and sent victims’ machines an uninstall command. Operation Endgame went after the broader ecosystem. In May 2024, it shut down over 100 servers and confiscated more than 2,000 domains, targeting IcedID, SystemBC, PikaBot, SmokeLoader, Bumblebee and TrickBot together. A 2025 phase hit DanaBot, QakBot and others, and US prosecutors charged 16 people tied to DanaBot.
Sinkholes, Sanctions and Arrests
Sinkholes, sanctions and arrests are the three main tools used against botnets. A sinkhole redirects infected machines to a server defenders control, so the operators can no longer send commands. The Conficker Working Group did this by registering all possible command-and-control domains before the attackers could. In the ZeroAccess case, Microsoft seized control of 49 domains. Sanctions target operators who are out of reach of arrest. The US and UK sanctioned members of the TrickBot group in 2023. Arrests and indictments hit individuals directly. Authorities charged a 23-year-old in April 2026 with developing and operating the Kimwolf botnet, and the Justice Department charged Rustam Gallyamov with leading the group behind QakBot. Europol has pointed out that even when operators stay out of court reach, authorities can still compromise and take down their botnets and infrastructure.
Why Botnets Come Back (Emotet, DanaBot and Beyond)
Botnets come back because takedowns remove infrastructure, not operators, malware code, or customer demand. Emotet returned in late 2021, months after the 2021 takedown, and has run in bursts since. DanaBot’s operators were charged in 2025, yet analysts said QakBot and DanaBot infrastructure was still active that year, with up to 1,000 infections a day. The strongest recent example is Aisuru. Four months after the March 2026 takedown, its known server infrastructure had more than doubled compared with before. Kimwolf was no longer active, but more than 20 rival botnet families adopted its techniques. Researchers also saw Kimwolf reactivating just ten days after the takedown. Defenders should plan for botnets returning under new names, which is why detection and patching still matter after a takedown.
How to Detect a Botnet Infection
A botnet infection shows up in four places: odd network traffic, changes on the infected host, matches against known indicators of compromise (IOCs), and stolen credentials appearing for sale. No single signal is reliable, so defenders combine them. Some botnets are easy to spot because one worm contacted 250 pseudorandom domains daily to receive instructions.

Network Indicators: C2 Traffic, DGA Domains, Unusual Ports and JA3 Fingerprints
Network indicators of a botnet include regular outbound connections to command-and-control (C2) servers, bursts of failed lookups for random-looking domains, scanning on unusual ports, and TLS fingerprints that match known malware. Infected machines tend to check in at steady intervals, which stands out against normal traffic. Domain generation algorithms (DGAs) create many domains a day, so a host producing dozens of failed DNS lookups for gibberish names is suspicious. Worms such as Conficker scan for SMB, and Mirai-style bots scan for Telnet on ports 23 and 2323, so outbound scanning from a printer, camera, or router is a strong signal. JA3 fingerprints hash how a client starts a TLS connection, and some families, such as TrickBot, have had distinctive JA3 values. Legitimate software can share a fingerprint, and operators can change TLS settings, so use a JA3 match as a lead, not proof.
Host Indicators: Persistence, Scheduled Tasks and Antivirus Detection Names
Host indicators of a botnet infection are persistence mechanisms, disabled security tools, unexplained system behavior, and antivirus alerts that name a known family. Loaders typically survive reboots through registry Run keys, scheduled tasks, or new services. A QakBot campaign analyzed by Zscaler created a registry key and stored an encoded PowerShell command in it to download and run the payload. Conficker turned off Windows updates and antivirus protection, so a machine that suddenly cannot update or reach security sites deserves a closer look. Detection names such as Win32/Emotet, Trojan.Emotet, Trojan.TrickBot and Win32/Conficker vary by vendor. A hit on any of them means the machine is infected and the attacker may have installed something else. On IoT devices, Mirai runs in memory, so a reboot removes it, but the device often reinfects within minutes unless you change the default password.
IOCs and MITRE ATT&CK Mapping for Each Family
IOCs are the concrete artifacts of a botnet, such as file hashes, C2 IP addresses and domains, mutex names, and TLS fingerprints. MITRE ATT&CK maps the behavior behind them. IOCs go stale quickly because operators rotate infrastructure, so they work best for hunting recent activity. ATT&CK entries last longer because behavior changes more slowly than infrastructure. Emotet is listed as software S0367 and Conficker as S0608. MITRE describes Conficker as a worm that spread using the MS08-067 Windows vulnerability and notes that it also relied on dictionary attacks against administrator passwords. Those map to exploitation of remote services (T1210) and brute force (T1110). TrickBot’s spread through EternalBlue and EternalRomance maps to T1210 as well. QakBot’s delivery chains changed often, moving through OneNote files, HTML smuggling, and ZIP archives. Check each family’s page on attack.mitre.org for current mappings, and pair it with CISA advisories and abuse.ch feeds for fresh IOCs.
Spotting Botnet Credentials for Sale on the Dark Web
Botnet infections often appear on the dark web as stolen credentials and session data for sale, sometimes before victims notice anything. Many loaders and stealers collect saved passwords and browser cookies from infected machines and sell them in packages called logs. The Genesis Market, taken down in 2023, offered data stolen from over 1.5 million compromised computers, including over 80 million account-access credentials. Its listings were sold as a subscription, sometimes updating login credentials as victims changed their passwords. Other marketplaces selling logs still operate. Organizations can monitor stealer logs and marketplaces for their corporate domains, employee emails, and session cookies. When a match turns up, treat the user’s device as compromised. Reimage it, then reset passwords and revoke active sessions, since a password reset alone won’t invalidate a stolen session cookie.
How to Stop and Remove Botnet Malware
To stop a botnet infection, take the infected device off the network immediately, change the credentials it touched, and then clean or rebuild the machine. Prevention matters more than cleanup. CISA warned that Emotet infections have cost state and local governments up to $1 million per incident to remediate.
Immediate Containment Steps
When you suspect a botnet infection, prioritize stopping it from spreading and stealing more. Disconnect the device from Wi-Fi and Ethernet, but leave it powered on if you need forensic evidence. CISA’s Emotet guidance advises organizations to identify the infection, shut down the infected machines, remove them from the network, and avoid logging in with domain or shared local administrator accounts. Using privileged accounts on a compromised machine may accelerate malware spread. Next, from a clean machine, change passwords for every account used on the device and revoke active sessions and tokens. Then check what else the infection did. Look for new mailbox rules, new accounts, and traffic to other internal machines. A botnet infection is often only the first stage, so treat it as a possible ransomware incident until you have ruled that out.
Removing Emotet, TrickBot and Conficker Infections
The safest way to remove Emotet or TrickBot from a business machine is to reimage it, since both install additional malware and steal credentials. For Emotet, CISA recommends reimaging the infected machines and reviewing log files and Outlook mailbox rules for the affected user account. The same approach suits TrickBot. After reimaging, reset every password stored or used on the machine, and check whether the attacker moved to other systems, particularly domain controllers. TrickBot spread through the EternalBlue SMB flaw, so patch Windows and disable SMBv1. Conficker is different because it is an older worm that mostly affects unpatched or pirated Windows systems. Researchers noted that many infected PCs ran bootlegged Windows and couldn’t download patches or Microsoft’s Malicious Software Removal Tool. To remove it, install the MS08-067 patch, disable AutoRun on removable drives, change any weak administrator passwords, and scan with an up-to-date antivirus from trusted media. If the machine still behaves oddly, rebuild it.
Hardening IoT Devices Against Mirai-Style Recruitment
You can harden IoT devices against Mirai-style botnets by changing default credentials, closing remote-access services, and keeping firmware updated. Mirai spreads by guessing factory-default logins, so unique, strong passwords on every router, camera, and DVR block most infections. Turn off Telnet, remote management, and UPnP unless you need them. Keep IoT devices on a separate network, so a compromised camera cannot reach your computers. Mirai lives in memory, so a reboot removes it, but the device will be reinfected unless you fix the password and exposure first. Newer botnets exploit other weaknesses. Kimwolf mainly infected Android devices with the Android Debug Bridge left open, and it took over more than 2 million non-certified Android TV boxes, so avoid uncertified boxes and turn off debugging on any Android device you own. Retire devices that no longer receive security updates.
Email, Patching and Credential Hygiene That Blocks Loaders
Most loaders arrive by email and succeed because of unpatched systems and reused credentials, so fix those three controls first. CISA and MS-ISAC recommend blocking suspicious attachments such as ZIP files, using email gateway filters, and enabling multifactor authentication. Attackers adapt quickly. When Microsoft restricted macros, QakBot operators began spreading through OneNote files, so review which file types your mail filters block rather than relying on a single rule—and patch internet-facing systems and Windows SMB flaws quickly, since worms and loaders exploit known bugs. Give users the minimum access they need, so a stolen account cannot reach everything. Add multifactor authentication, preferably phishing-resistant, and keep tested offline backups. Finally, monitor for your organization’s credentials appearing in stealer logs, because stolen passwords can be used even after you remove the malware.
Botnet Trends: What’s Changing in 2026
The biggest botnet trends in 2026 are command infrastructure that is harder to seize, recruitment through residential proxy networks, and the steady reuse of Mirai code in new variants. Takedowns have not reduced the scale. According to the team behind the original Kimwolf disruption, daily active DDoS endpoints rose from about one million to 8–9 million within a year.
Decentralized C2: From Storm Worm to IPFS and Blockchain
Decentralized command and control (C2) is a design in which no single server or domain can be seized to shut a botnet down. The idea is not new. The Storm worm used peer-to-peer communication in 2007, and later families such as GameOver Zeus and ZeroAccess did the same. The 2026 version relies on public infrastructure that defenders cannot take down. After several domain takedowns, Kimwolf’s operators turned to EtherHiding, which hides C2 data in Ethereum Name Service (ENS) records. Version 7 goes further, with five hard-coded public Ethereum endpoints for resolving ENS domains, plus a hard-coded Tor hidden service and a local proxy as backups. Unit 42 describes this as infrastructure built to withstand takedown operations. Defenders can no longer rely on blocking a list of domains. They need to watch for unexpected blockchain RPC and Tor traffic from devices that have no reason to use either.
Residential Proxy and IoT Botnets at Scale
Residential proxy networks have become a major recruitment channel for IoT botnets because they give attackers a path to devices normally hidden behind a home router. Kimwolf exploited a vulnerability in Ipidea’s proxy infrastructure to tunnel back through the proxy network and compromise local-network devices. Google called Ipidea one of the world’s largest residential proxy networks and obtained a court order in January 2026 to remove dozens of its domains. In one seven-day window that month, Google observed more than 550 individual threat groups using Ipidea exit nodes to obscure their activities. The result is a market in which a single compromised TV box can serve as both a DDoS node and a proxy for sale. Most victims are consumers, and many don’t know a device is infected. Home users should avoid uncertified Android TV boxes and cheap devices that ship with remote debugging enabled.
Latest Mirai Activity, Port 139 Scans and New C2 Infrastructure
Mirai remains one of the most active botnet families in 2026, mostly through new variants that add newer exploits to the same scanning model. A Mirai-based botnet named xlabs_v1 exploits internet-exposed Android Debug Bridge (ADB) on port 5555 to enlist devices for DDoS attacks, and it targets Android TV boxes and set-top boxes. A March 2026 sandbox analysis of an EchoBot/Mirai sample found that a 99 KB binary contacted 238,756 hosts in 149 seconds. Classic Mirai scans still show up in network data. An academic study found the Mirai signature still in use in 2022, with most probes aimed at Telnet port 23 and fewer at 2323. Defenders should watch for scanning on Telnet, ADB, and SMB/NetBIOS ports, including TCP 139, since worm-like scanning from a device that should be silent is a strong sign of compromise. On the infrastructure side, Aisuru shows how quickly operators rebuild. Four months after the March 2026 takedown, its known server infrastructure had more than doubled compared with before the operation.
Frequently Asked Questions (FAQ)
What is the most dangerous botnet ever?
No single botnet is the most dangerous on every measure, so the answer depends on what you count. Europol called Emotet “the world’s most dangerous malware” when it took the botnet down in 2021 because it opened the door to ransomware for thousands of organizations. Conficker infected the most machines, with estimates ranging from almost 9 million to 15 million computers. Aisuru and Kimwolf produced the most powerful attacks. Together with related botnets, they at times controlled more than three million devices and were linked to attacks of roughly 30 terabits per second. Mirai arguably had the most lasting influence, because its leaked code still underlies many botnets today.
Is Emotet still active?
Emotet has not disappeared, but it is no longer the dominant threat it was before 2021. When authorities disrupted it in January 2021, it had infected more than 1.6 million computers globally. It returned around November 2021, rebuilt with help from TrickBot, which installed Emotet on machines it had previously infected. Activity then grew quickly. Kaspersky tracked malicious emails rising from about 3,000 in February 2022 to about 30,000 in March. Since then, it has run in bursts separated by quiet periods. Treat it as dormant but capable of returning, and check current tracking from Cryptolaemus and abuse.ch’s Feodo Tracker before assuming either way.
Is Conficker still a threat?
Conficker remains a threat to unpatched and legacy systems, though it is a minor risk for up-to-date computers. The worm exploited the Windows flaw patched in MS08-067, so machines with that patch are protected from its main infection route. It persisted for years because many infected PCs could not be cleaned. Microsoft counted about 1.7 million infected or targeted PCs in the fourth quarter of 2011, three years after it first appeared. It also still turns up in industrial and embedded settings. MITRE records that a variant reached computers and removable drives at a nuclear power plant in 2016. If you find Conficker on a system, it usually means the machine has been neglected for a long time.
What is the difference between Emotet and TrickBot?
Emotet is mainly a delivery botnet that spreads by email and installs other malware, while TrickBot is a modular trojan that steals credentials and moves through a network. Both began as banking trojans, Emotet in 2014 and TrickBot in 2016. In the classic attack chain, they worked together. Emotet dropped QakBot and TrickBot, which in turn deployed Ryuk and Conti ransomware. Emotet got the first foothold, TrickBot expanded it, and ransomware finished the job. Authorities disrupted both separately. Authorities took down Emotet in January 2021, and in 2024 German authorities were seeking seven people tied to the group that spread TrickBot.
How many devices did Mirai infect at its peak?
Mirai peaked at about 600,000 infected devices. A study by researchers from Georgia Tech, Google, Cloudflare, Akamai, and others tracked a peak of 600,000 infections at the end of November 2016, falling to about 100,000 by the end of February 2017. The botnet infected nearly 65,000 IoT devices in its first 20 hours before settling at 200,000–300,000. The victims were mostly cameras, DVRs, and routers with default logins.
How can I tell if my device is part of a botnet?
Common signs include unusual slowness, high network activity when the device is idle, security tools that stop working, and connections to unfamiliar addresses. On a computer, check for antivirus alerts, unfamiliar programs, and security updates that suddenly fail. On a router or camera, look for unknown logins, changed settings, or a device you can no longer manage. For Android TV boxes, check whether debugging is open, since Kimwolf mainly infected Android devices with the Android Debug Bridge left open. Synthient released a public tool that checks whether an Android device is part of the Kimwolf botnet. If you suspect an infection, disconnect the device, scan it with an up-to-date antivirus, factory-reset IoT devices, and change every password they used.


