Skip to main content Blog Accessibility Access to Broadband AI for Good COVID-19 Cybersecurity Digital Safety Fundamental Rights Journalism Open Data Philanthropies Privacy Responsible AI Skills Sustainability United Nations Washington State Tools and Weapons Today in Technology Microsoft Philanthropies Microsoft on Data Law Microsoft TechSpark Microsoft Environmental Sustainability Cloud for Global Good Microsoft 365 Azure Copilot Windows Surface XBOX Deals Small Business Support Windows Apps Outlook OneDrive Microsoft Teams OneNote Microsoft Edge Moving from Skype to Teams Computers Shop XBOX Accessories VR & mixed reality Certified Refurbished Trade-in for cash XBOX Game Pass Ultimate PC Game Pass XBOX games PC games Microsoft AI Microsoft Security Dynamics 365 Microsoft 365 for business Microsoft Power Platform Windows 365 Small Business Digital Sovereignty Azure Microsoft Developer Microsoft Learn Support for AI marketplace apps Microsoft Tech Community Microsoft Marketplace Software companies Visual Studio Microsoft Rewards Free downloads & security Education Gift cards Licensing Unlocked stories View Sitemap

What is a botnet and how can you stay safe online?

Has your computer ever sent spam emails or run more slowly than usual? These symptoms could mean it’s part of a botnet.

But what is a botnet, how does it work and what can you do to protect yourself online?

Botnets are networks of computers infected by malware and being used to commit cybercrimes.

The cybercriminal or “bot master” uses special malware – called Trojans – that sometimes appear in an infected email attachment or in a link that you can be tricked into opening. Once it’s on your device, the botnet will contact its command-and-control center.

[READ MORE: How Microsoft’s Digital Crimes Unit fights cybercrime]

The attacker can now control your device remotely, or even communicate with other infected devices, to commit identity theft and financial fraud, send out millions of spam emails, or even shut down websites in distributed denial-of-service (DDoS) attacks.

Sometimes, the cybercriminal will establish a large network of bots and rent out or sell access to the zombie network to other criminals.

[READ MORE: Online scammers cost time and money. Here’s how to fight back]

How to avoid being attacked

How do you protect yourself?

Follow these key steps to make sure you’re not at risk:

  1. Make sure you have antivirus software on your devices that checks for malware and removes it. It’s worth noting that Windows 10 and Windows 8 have Windows Security or Windows Defender Security Center already installed.
  2. Use a firewall – Windows 10 and Windows 8 have an in-built firewall that is automatically on.
  3. Keep Windows or your operating system up to date by setting your machine to automatically install updates.
  4. Don’t download any suspicious attachments or click on unusual links in messages. They might be disguised as coming from trusted sources.
  5. Browse the web safely and use a modern browser such as Microsoft Edge, that can help to block malicious websites and code. Only download software from trusted websites.
  6. Make sure your passwords are protected.

For more on cybersecurity and the work of Microsoft’s Digital Crimes Unit, visit Cybersecurity. And follow @MSFTIssues on Twitter.  

English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Microsoft Privacy Manage cookies Terms of use Trademarks Safety & eco Recycling About our ads