216.73.217.22

T1584.005: T1584.005

View on MITRE ATT&CK The MITRE Corporation · Published 16/12/2025 19:38 · Modified 13/04/2026 17:48

Essential information

MITRE technique ID
T1584.005
Confidence
100/100
Revoked
No
Published
16/12/2025 19:38
Modified
13/04/2026 17:48
Author / Source
The MITRE Corporation

Aliases

Botnet

Platforms

PRE

Description

Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks.(Citation: Norton Botnet) Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems.(Citation: Imperva DDoS for Hire) Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers.(Citation: Dell Dridex Oct 2015) With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale [Phishing](https://attack.mitre.org/techniques/T1566) or Distributed Denial of Service (DDoS).

Kill chain phases

Kill chainPhase
mitre-attack resource-development

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references