Has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations.1
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.0
- Created
- 01 October 2020
- Last modified
- 12 May 2026
Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks.[1] Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems.[2] Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers.[3] With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS).
Botnet MITRE reference T1584.005
5 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has used compromised devices in covert networks to obfuscate communications.1
Has used a botnet management interface to control large numbers of compromised hosts.1
Has used a large-scale botnet to target Small Office/Home Office (SOHO) network devices.1
Has used large groups of compromised machines for use as proxy nodes.1
All 5 groups for this technique
Offense vs defense T1584.005
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
Botnet detection strategy DET0883
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Botnet
AN2015 · PRE
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Phishing, Endpoint Denial of Service, or Network Denial of Service.
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.