Botnet
In plain terms
Your device has been recruited into a network that attacks other targets. You aren't the intended victim: you're the instrument, which is why nothing alerts you.
Definition
A botnet is a set of compromised devices, remotely controlled by a single operator, and used collectively to send spam, overwhelm services, relay traffic, or test stolen credentials. The recruited device isn't the target of the attack: it's the instrument.
How it works
Recruitment follows the usual paths — a trojan program, an unpatched software flaw, a default password on a connected device. What sets this case apart is the business model, from which everything else follows: a recruited device's value lies in numbers, not in what it contains. The program is therefore tuned to stay unnoticed, using only a fraction of the machine's resources. That's why connected devices — cameras, recorders, routers, network printers — are prime targets: always on, rarely updated, and without a screen to flag anything. The only visible sign often comes from outside: an internet provider flagging unusual activity, a blocked address, messages that no longer reach their destination.
Warning signs
- Warning from your internet provider about unusual activity on your line
- Your emails end up in recipients' spam folders, or your address gets rejected
- Continuous outgoing traffic while nobody is using the network, especially at night
- IP address blocked by websites, or anti-robot checks that have become constant
- A connected device running hot or responding poorly with no change in how it's used
How to verify
Look at the traffic rather than the device: in your router's interface, the list of connected devices and their consumption at a time when nobody is active is the most accessible clue. A device transmitting continuously at night deserves a closer look. Take seriously any report from your internet provider — it's often the most reliable information you'll have.
What to do
Change the default passwords of everything connected, including the router, and enable automatic updates. Disable remote access on equipment that doesn't need it. Remove from the network any devices that no longer receive updates from their manufacturer.
If it already happened
Identify the device involved from the router's interface, then reset it to factory settings and update it before putting it back into service — for a screenless connected device, that's generally the only option available. Then change its password and the router's. If the device no longer receives updates, don't plug it back in. Report the incident to cybermalveillance.gouv.fr.
Frequently asked questions
- Am I at risk even though I'm not the target?
- Yes, in two ways. The first is concrete and immediate: your line can be blocked, your address rejected, your connection degraded. The second is that the access that allowed the recruitment stays open and can be used for something else — a recruited device is a controlled device.
- My computer seems normal — is that possible even so?
- It's the most common case, and it's deliberate: a device that lags gets fixed, and so gets lost to the operator. The method only pays off through numbers, which makes discretion worthwhile.
Related attacks
Official sources
Also known as: botnet, zombie device network, zombie machine, zombie device.
This article is part of the Malware family. Last updated: 2026-09-03.