High severity Malware

Botnet Client

An infected machine that takes orders from a command-and-control server and joins a wider swarm.

Overview

Once enrolled, the host can be told to flood a target, proxy traffic, mine currency or spray credentials.\nModern botnets recruit through the Mirai-style default-credential playbook against routers, cameras and DVRs as readily as against servers.\nOutbound C2 filtering and taking over the DNS infrastructure are the standard disruption routes.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Beaconing to one host on a fixed interval
  • Devices logging in with vendor default passwords
  • Unexpected outbound traffic on odd ports

Controls that stop it

  • Segment the Network and Restrict Egress

    Do not let every host talk to every other host or to the whole internet. Segment by role, deny inbound administration from user networks, and filter outbound traffic so only the destinations a workload genuinely needs are reachable. Egress control is what stops an SSRF or an implant from reaching cloud metadata and command infrastructure.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used