Inside IoT Botnet Ecosystem: A Review of its Evolution, Architecture, & Security Lifecycle
Happy Happy, Rita Rana Chhikara, Neeti Kashyap · 2025
Internet of Things (IoT) botnets have become a severe cybersecurity threat to IoT devices because they exploit vulnerable devices to conduct computationally efficient attacks, which include distributed denial-of-service operations and data breaches alongside resource hijackings. This review research analyses the complete nature of IoT botnets through their key features together with their links to conventional botnets and their historical timeline. In this review, we look at a number of different architectural designs, such as centralised and decentralised (P2P), hybrid, and new HTTP2P models, to see how they affect, how botnets work and how long they can stay alive. Additionally, a complete breakdown of botnet operational development follows a complete sequence starting from recruitment and interaction towards propagation and communication until the execution phase of attacks. This study also looks into the main ways that IoT botnets are used for attack, as well as a lot of information about how to find and protect IoT devices using honeynet, signature and anomaly intrusion detection systems, and data mining with machine learning techniques. The aim of this research is to deliver complete knowledge about IoT botnet structures to security experts and researchers while offering useful strategies for strengthening cyber defence capabilities.