In the field of cybersecurity, the names ZeuS, Andromeda, Emotet, TrickBot, and Storm have little to do with mythology or natural disasters. They are also names given to botnets or malware used to steal data from computers.
A botnet is not simply a collection of infected computers. It is a network of remotely controlled devices in which each device is used without its owner’s knowledge for large-scale attacks, data theft, spam distribution, or advertising fraud. Botnets can include computers, servers, smartphones, and even household devices connected to the Internet.
At the heart of a botnet is malware that reaches a device through phishing emails, malicious links, or software vulnerabilities. Once infected, the device connects to the botnet’s command-and-control infrastructure, allowing its operator—the “botmaster”—to send instructions to numerous members of the network. As a result, instead of a single attacker, thousands or even millions of devices located in different countries can be involved in an attack. This geographical diversity also makes it more difficult to identify the source of the attack.
In some cases, a botnet can even become a “service” that cybercriminals offer to others. One of the most well-known uses of botnets is for DDoS attacks, in which large numbers of devices simultaneously overwhelm a website or online service, making it unavailable to users.
For example, Mirai, which became widely known in 2016 after successfully targeting a company providing DNS services, was able to “recruit” Internet-connected household IoT devices, among others, into its network.
Following the publication of Mirai’s source code, numerous new variants and IoT botnets emerged, demonstrating how household devices could be turned into tools for cyberattacks. ZeuS, meanwhile, highlighted another dangerous use of botnets: the theft of financial information. Users in 196 countries were reportedly among the victims of ZeuS, with losses exceeding $100 million.
Another major example is Emotet, which began as a banking Trojan but later evolved into an infrastructure widely used by cybercriminals. In 2021, an international law-enforcement operation disrupted its infrastructure. According to the U.S. Department of Justice, Emotet had infected more than 1.6 million computers and caused hundreds of millions of dollars in damage worldwide.
The main danger posed by botnets is not only the malware itself, but also their scale. By bringing large numbers of devices together and controlling them as a single system, botnet operators gain the ability to disrupt businesses, organizations, and even major Internet infrastructure.
Therefore, combating botnets requires not only the work of cybersecurity professionals but also vigilance from every Internet user. Keeping devices and software up to date, using strong passwords, and being cautious with suspicious emails and links can reduce the likelihood of a device being turned into a “soldier” for cybercrime.




























