๐Ÿ”„ Topic

Understanding botnets, IoT malware, and how compromised devices are coordinated at scale.


๐ŸŽฏ Goal

Learn how botnets operate and what network behaviors can reveal compromised devices.


๐Ÿ›  What I Did

Today I studied botnets and IoT malware.

A botnet is a group of compromised devices controlled by an attacker.

Each compromised device is called a bot.

The attacker controls the bots through command-and-control infrastructure.

IoT devices are common botnet targets because they often have weak security.

Examples include:

  • routers
  • cameras
  • smart appliances
  • DVRs
  • printers
  • poorly managed embedded devices

These devices may have:

  • default passwords
  • outdated firmware
  • exposed services
  • limited logging
  • weak monitoring
  • poor patching processes

Once compromised, botnet devices can be used for:

  • distributed denial-of-service attacks
  • scanning for more victims
  • proxying malicious traffic
  • spam
  • credential attacks
  • cryptomining

๐Ÿ”— Key Cybersecurity Connections

Botnets matter because they multiply attacker power.

One compromised device is a problem.

Thousands or millions of compromised devices become infrastructure.

For defenders, botnets often appear through network behavior:

  • many devices contacting the same command-and-control server
  • repeated beaconing
  • unusual outbound connections
  • traffic to rare domains
  • scanning activity
  • abnormal DNS queries
  • high traffic volume from devices that should be quiet

IoT devices make the problem harder because many do not produce useful logs.

That means network monitoring becomes essential.


๐Ÿ” Investigation Questions

  • Which device is generating unusual traffic?
  • Is the device expected to access the internet?
  • What destination is it contacting?
  • Is the traffic periodic?
  • Is it contacting a known malicious IP or domain?
  • Is the device scanning internal or external IP ranges?
  • Does the device have default credentials?
  • Is the firmware outdated?
  • Are multiple similar devices showing the same behavior?
  • Can the device provide logs?
  • Should the device be isolated from the main network?

๐Ÿšจ Detection Opportunities

Possible detection ideas:

  • IoT device contacting rare external domains
  • repeated beacon-like traffic
  • device scanning many IP addresses
  • outbound traffic from cameras or printers to unusual countries
  • many internal devices contacting the same external IP
  • DNS queries for known botnet infrastructure
  • unusual traffic volume from normally quiet devices
  • default credential login attempts
  • Telnet or SSH exposure on IoT devices

Example detection pattern:

device_type=camera
destination_ip=rare_external_ip
interval=30 seconds
outbound_connections=consistent
suspicion=possible_botnet_beaconing

Another example:

source_device=router
destination_port=23
unique_destinations=1000
suspicion=IoT_scanning_activity

๐Ÿงญ MITRE ATT&CK Techniques

  • T1071 โ€” Application Layer Protocol
  • T1095 โ€” Non-Application Layer Protocol
  • T1046 โ€” Network Service Discovery
  • T1498 โ€” Network Denial of Service
  • T1110 โ€” Brute Force

๐Ÿ—บ Visual Investigation Diagram

Vulnerable IoT device
    โ†“
Compromise
    โ†“
Bot checks in with C2
    โ†“
Attacker sends command
    โ†“
Bot scans, attacks, or mines
    โ†“
SOC detects abnormal network behavior

โš  Challenges

The main challenge is visibility.

Normal endpoints may have EDR, logs, and process telemetry.

Many IoT devices do not.

A camera may not tell you:

  • which process ran
  • what command executed
  • what file changed
  • which user logged in

So defenders often need to rely on:

  • network segmentation
  • firewall logs
  • DNS logs
  • NetFlow
  • asset inventory
  • traffic baselines

Another challenge is that IoT devices are often forgotten after installation.

They may sit on the network for years with old firmware and weak passwords.


๐Ÿ“š What I Learned

I learned that botnets are not only a malware issue.

They are also an asset management issue.

If an organization does not know what devices it owns, it cannot properly defend them.

I also learned that IoT security often depends heavily on network controls because endpoint visibility may be weak.


โžก Next Steps

  • Study Mirai-style IoT botnets
  • Learn common IoT attack paths
  • Practice identifying beaconing traffic
  • Review network segmentation for IoT devices
  • Build a botnet detection note with C2 indicators
  • Compare botnets with cryptomining malware and DDoS attacks

๐Ÿง  Reflection

Botnets show how small weak devices can become part of something much larger.

A single insecure camera may not seem important.

But at scale, compromised IoT devices can become a weaponized network.

That is a powerful lesson for defenders.


๐Ÿงฉ Lessons Learned

What worked

Thinking about botnets as coordinated infrastructure, not isolated infections.

What broke

Assuming only laptops and servers matter.

Why it broke

Attackers compromise whatever gives them scale, including weak IoT devices.

Fix / takeaway

Every network-connected device is part of the attack surface.


๐Ÿ“ˆ Skill Progression Context

This supports SOC and network security monitoring skills.

Botnet detection requires understanding beaconing, DNS activity, traffic baselines, IoT risk, and command-and-control behavior.


๐Ÿ˜„ TL;DR

A smart camera with a dumb password can become a soldier in someone elseโ€™s army.