What Is a Botnet? Is Your Router Part of One?

Home routers are always on and rarely checked, which makes them ideal recruits.

Published October 2026 · ismyroutersafe.com

A botnet is a network of hacked devices that an attacker controls remotely. Home routers are frequent targets. US government advisories from 2016 to 2025 describe router botnets used for attacks, spying and hiding criminals’ traffic. The ones below were built from routers with default passwords, unpatched flaws or no support.

What is a botnet?

The FBI and NSA describe it as a network of devices infected with malware that gives attackers unauthorized remote access. It can deliver malware, launch denial-of-service attacks or route criminal traffic.

Your router keeps working. It just also works for someone else.

Rio Router
From the team behind this checker
Want a router that takes this seriously by default?
  • SecureRooms. Smart devices live apart from your computers.
  • You approve every new device before it joins.
  • Rio VPN built in. First year included.
  • Set up in about 10 minutes from the app.
See Rio Router →
$199.99 · 1 year of VPN included, then $7.99/mo · 30-day returns · 1-year warranty. Rio builds this site and grades its own router by the same method.

How routers get recruited

What router botnets are used for

Botnets the US has warned about

For the China-linked campaigns, see our Typhoon explainer.

Is your router in a botnet?

Often you cannot tell. The FBI said VPNFilter’s use of encryption made its activity hard to detect. It lists overheating, connection problems and unrecognized setting changes as common signs. See hacked router signs.

How to stay out of a botnet

  1. Update the firmware, automatically where offered.
  2. Replace default passwords with strong, unique ones.
  3. Turn off remote management and UPnP unless you need them. The FBI says attackers abuse them.
  4. Reboot weekly, as the NSA recommends. Some malware lives only in memory.
  5. Separate smart devices, as the FBI and NSA advise.
  6. Replace end-of-life routers with supported models.

Fastest first step: check your router’s grade to see support status and known flaws.

Frequently Asked Questions

Yes. The FBI and NSA said many devices in a 2024 botnet of 260,000 were likely still supported by their makers. Supported routers still need updates installed and default passwords changed.

Sometimes. CISA says Mirai lives in memory, so a reboot clears it, but reinfection can be quick if the password is not changed. For some hacked routers, the FBI and NSA advise a factory reset and firmware update.

The FBI notified owners of infected routers during its court-authorized operation, or asked internet providers to pass on notice. The Justice Department said the vast majority were end-of-life Cisco and NetGear routers.

Both criminals and governments. US advisories describe botnets run by criminal proxy services, Russian military intelligence, and a China-based company linked to Flax Typhoon.

Report it to the FBI’s Internet Crime Complaint Center at ic3.gov. The Justice Department also points to CISA’s online reporting.

Sources

Dates show when each source was published or when we checked it.

CHECK YOUR ROUTER

See how your router scores

Get its FCC status, CVEs, grade and an action plan.

Check a Router → Top 10 Safe Routers
Rio Router is the only router we rate A. Rio builds this site. See why →