A botnet is a network of compromised devices that an attacker controls remotely to run automated fraud at scale. Because the traffic comes from thousands of real, scattered machines, a botnet lets attacks like credential stuffing and card testing hide inside normal-looking activity.
What is a botnet?
A botnet is a fleet of hijacked devices under one attacker's control. The devices can be laptops, servers, phones, or connected gadgets like cameras and routers, infected by malware and quietly waiting for instructions. The operator, sometimes called a bot herder, sends commands from a control server and the whole fleet acts in unison.
What makes a botnet valuable to a fraudster is distribution. Instead of hammering a target from one address that is easy to block, the attacker spreads the work across thousands of machines, each contributing a small slice. The traffic looks like it comes from many ordinary users in many places, because in a sense it does.
In fraud and payments, botnets are the engine behind high-volume automated abuse: testing stolen card numbers, stuffing leaked credentials into login pages, creating fake accounts, scraping data, and scalping limited stock. If an attack needs scale and needs to blend in, a botnet is usually how it is delivered.
How a botnet is built and used
Botnets follow a lifecycle from infection to attack, and the same fleet can be rented out for many different jobs.
- InfectCompromise devices Malware spreads through phishing, weak passwords, or unpatched software, quietly enrolling each device into the network.
- CommandConnect to control Infected machines phone home to a command server and wait for instructions, often idle so the owner never notices.
- DeployRun the attack The herder pushes a job: credential stuffing, card testing, fake signups, scraping, or scalping across the whole fleet.
- MonetizeSell or reuse Working accounts and cards are cashed out, and the botnet is rented to the next buyer for the next campaign.
What it looks like in practice
A lender's login page starts seeing a surge of attempts using email and password pairs from an old breach. The requests arrive from tens of thousands of different home internet addresses, a few tries each, spread over hours so no single address trips a rate limit.
That is a botnet running credential stuffing through residential connections. Because each device does so little, per-address blocking barely dents it. The team only gets ahead once it stops looking at single IPs and starts correlating shared device traits, timing, and the reused breach data across the whole wave, then challenges and throttles by those patterns.
Why botnets are hard for operators
The whole point of a botnet is to defeat the simplest defenses. Blocking a bad IP does nothing when the next request comes from a different home connection, and rate limits set per address never trip because each device stays under the threshold. The traffic is real devices in real places, which strips away the easy tells that flag a single abusive machine.
That forces defenders up a level. Instead of chasing addresses, effective teams look for the coordination that a botnet cannot hide: the same leaked credentials, similar device and browser traits, matching timing, and downstream behavior that no honest cohort would share. Botnets are also increasingly rented as a service, so the same fleet can hit you with card testing one week and fake signups the next.
What to watch in the data
- Distributed low-and-slow. Many addresses each making a few attempts, timed to stay under per-IP limits, is the signature of a botnet.
- Residential proxy traffic. A jump in logins or checkouts from rotating home-ISP addresses often means an attacker is renting cover.
- Shared device traits. Different IPs that share fingerprints, headers, or automation markers reveal one operator behind many machines.
- Correlated failures. Spikes of failed logins or declines that cluster in timing and reuse the same breach data point to coordinated automation.
- Odd device geography. Connected devices in unusual locations acting like browsers can indicate infected hardware pressed into service.
Quick questions
Are the botnet devices owned by criminals?
Usually not. Most are ordinary devices, from home computers to routers and cameras, infected without the owner's knowledge. The owner keeps using the device normally while it quietly runs attacks in the background.
Why can't I just block the bad IPs?
Because a botnet spreads across thousands of legitimate-looking addresses, each making only a few requests. Blocking one does nothing, and blocking broadly risks cutting off real customers, so defenders correlate behavior across addresses instead.
What fraud do botnets power?
The high-volume, automated kinds: credential stuffing, card testing, fake account creation, content and price scraping, scalping limited stock, and denial-of-service floods. The same fleet can switch between these jobs on command.
What is botnet-as-a-service?
It is the rental model where an operator leases access to their fleet to other criminals by the hour or by the job. It lowers the skill needed to launch a large attack, since the buyer just supplies the target and the stolen data.
How do teams detect botnet traffic?
By looking past single addresses to shared signals: device fingerprints, timing patterns, reused credentials or card data, and coordinated downstream behavior. Bot detection and device intelligence tools exist to surface exactly this kind of coordination.
Qué saber junto con Botnet

Informe de Fraude y ALD 2026
Olvídate de las predicciones. Este informe desglosa a qué se enfrentan realmente los equipos de fraude y ALD, y cómo responder.
