Main content

Anatomy of a botnet DDoS attack

How compromised devices become weapons — and where the attack chain can be broken

waves

Anatomy of a botnet DDoS attack

How compromised devices become weapons — and where the attack chain can be broken

Most large DDoS attacks today are launched from botnets: networks of hijacked computers, servers, routers, IP cameras and other connected devices whose owners rarely know they have been recruited. Understanding how a botnet attack unfolds — stage by stage — also reveals where it is most vulnerable to disruption. This page walks through the five stages of a typical botnet DDoS attack, explains the roles of residential proxies and command-and-control (C2) infrastructure, and shows where defenders can break the chain.

Stage 1

Recruit: compromise or rent

Attackers build capacity by compromising connected devices — exploiting hard-coded credentials, unpatched firmware and vulnerable IoT platforms — or simply rent access to an existing botnet or residential proxy network. Some devices are enrolled through malware bundled with apps; others arrive compromised from a fragmented supply chain. Once enrolled, most devices remain in the botnet permanently.

Stage 2

Command: instructions from the C2

Compromised devices register with command-and-control servers and wait. When a campaign begins, the C2 layer distributes instructions — target, attack vector, timing — to thousands or millions of devices within seconds. The C2 layer is the botnet’s nervous system, and its single greatest weakness.

Stage 3

Launch: the attack begins

On command, the bots generate traffic toward the target: UDP or SYN floods, reflection and amplification vectors, or application-layer requests that mimic real users. Because the traffic originates from real devices on ordinary residential connections, it blends with legitimate activity — and modern campaigns shift vectors and targets within minutes.

Stage 4

Overwhelm: bandwidth, state and applications

The combined load consumes whatever the attack targets: link bandwidth, the connection tables of servers, firewalls and load balancers, or application resources such as databases and authentication. Legitimate users experience delays, errors or loss of access. The damage is not only inbound — outbound attack traffic from compromised subscribers also congests the host operator’s own network and poisons its IP reputation.

Stage 5

Persist: enrolled for the long term

When the attack ends, the devices stay enrolled, ready for the next campaign. Botnets that are disrupted fragment and re-form: after one major takedown, Nokia observed more than 20 smaller botnet families emerge, together generating up to 10,000 DDoS attacks per day.

infographic anatomy of a botnet ddos attack

What are residential proxies?

Residential proxies are networks that route third-party traffic through ordinary household internet connections, constantly rotating consumer IP addresses. Marketed as privacy and data-collection tools, they make malicious requests that appear to come from genuine subscribers — defeating IP reputation lists, geo-blocking, and rate limiting. Nokia research identified more than 100 million residential endpoints as potentially exploitable via residential proxy networks and related botnets, and found that the number of active residential-proxy endpoints associated with DDoS attacks grew from about 1 million to 8–9 million in a single year. Symmetric fiber broadband and industrial-scale AI web scraping have pushed the proxy economy from fringe fraud tool to mainstream infrastructure risk.

How does command and control (C2) work?

Command and control is the coordination layer between the botnet operator and the compromised devices. After infection, each device beacons to the C2 infrastructure — often a hierarchy of compromised servers — to announce its availability. Operators lease this capacity to customers, then push attack instructions through the hierarchy: which target, which vector, when to start, when to shift. Modern C2 layers rotate addresses and infrastructure rapidly to evade takedown and increasingly automate the campaign itself — monitoring the defender’s response and reshaping the attack in real time.

This coordination is also the defender’s opportunity. A million-device botnet with a silenced C2 layer is a million idle devices: block the instructions, and the swarm never fires.

How the attack chain is broken

Detect

Nokia Deepfield Defender correlates network-wide telemetry with Deepfield Secure Genome — Nokia’s hourly-updated security map of the internet, spanning more than 5 billion IPv4 and IPv6 addresses — to recognize botnet activity by who is sending the traffic, not just how much of it there is.

Disrupt the C2

Nokia Deepfield Genome Shield attacks the chain at its weakest link. Its disrupt botnet C2 pillar maintains continuously updated rule families for specific botnet and residential proxy C2 infrastructures and blocks communication between compromised devices and their command-and-control servers before attacks start — Nokia estimates these rules block over 99% of all DDoS C2 malicious traffic — so enrolled devices inside and outside the network never receive the instruction to fire.

Enforce in the network

Policies are pushed to the network through NETCONF, BGP FlowSpec and BGP RTBH, and enforced at line rate on Nokia (7750 SR, 7730 SXR, 7250 IXR) and third-party (e.g., Cisco, Juniper) routers, with the 7750 Defender Mitigation System handling fine-grained L4–L7 scrubbing for the most complex attacks. No diversions, no detours, no added latency.

Stay ahead

Genome Shield’s predictive protection keeps always-on rate limiters in place that suppress amplification and DDoS before detection even triggers, while custom policies and observability round out its four pillars. Explore Nokia Deepfield Genome Shield.

Frequently asked questions

Please complete the form below.

The form is loading, please wait...

Thank you. We have received your inquiry. Please continue browsing.