Zombie — IT Glossary | ITU Online IT Training
+1 855.488.5327 customerservice@ituonline.com Mon – Fri: 9:00am – 5:00pm ET

Zombie

Commonly used in Cybersecurity

Ready to start learning?Individual Plans →Team Plans →

In cybersecurity, a zombie is a computer or device that has been compromised by a hacker and is being controlled remotely without the owner's knowledge. These infected devices are often used as part of a larger network to carry out malicious activities, most notably distributed denial-of-service (DDoS) attacks.

How It Works

A zombie is typically infected through malware, which can be delivered via email, malicious websites, or software vulnerabilities. Once infected, the device becomes part of a botnet—a network of compromised computers controlled by a hacker or cybercriminal. The attacker can then command these zombies to perform specific actions, often en masse. This control is maintained remotely, often through command and control (C&C) servers, allowing the hacker to issue instructions without the device owner’s knowledge. The process usually involves stealthy malware that hides its presence and avoids detection by security software.

The infected device continues to function normally for the user, but it secretly becomes part of a larger malicious operation. The hacker can coordinate multiple zombies to execute tasks simultaneously, such as flooding a target website with traffic or sending spam emails, without the device owner realizing their device is being used for malicious purposes.

Common Use Cases

  • Launching distributed denial-of-service (DDoS) attacks to overwhelm targeted websites or networks.
  • Sending large volumes of spam emails to distribute malware or phishing campaigns.
  • Stealing sensitive information by using the zombie to infiltrate secure networks.
  • Mining cryptocurrencies covertly using the resources of infected devices.
  • Facilitating other cybercrimes such as click fraud or spreading malware.

Why It Matters

Understanding zombies is crucial for cybersecurity professionals, as these compromised devices form the backbone of many cybercriminal operations. Detecting and mitigating zombie infections helps protect networks from being used in large-scale attacks that can disrupt services or cause financial damage. For certification candidates, knowledge of zombie-related threats is essential for roles involving network security, incident response, and threat management. Recognising the signs of zombie activity and implementing effective security measures can significantly reduce the risk of becoming part of a botnet or being targeted by malicious campaigns.

Ready to start learning?Individual Plans →Team Plans →
Discover More, Learn More
Understanding the Security Operations Center: A Deep Dive Discover how a Security Operations Center enhances your cybersecurity defenses, improves incident… What Is a Security Operations Center (SOC)? Discover what a security operations center is and how it enhances organizational… Step-by-Step Guide to Implementing a Security Operations Center in Your Organization Discover how to effectively implement a security operations center in your organization… Building a Security Operations Center: A Complete SOC Setup Blueprint Discover how to build a comprehensive Security Operations Center to enhance cybersecurity… Understanding SOC Functions: The Complete Guide to Security Operations Center Operations Discover how SOC functions support security monitoring, threat detection, and incident response… Counterintelligence and Operational Security in Cybersecurity: A Guide for CompTIA SecurityX Certification Discover essential strategies to enhance your cybersecurity skills by understanding counterintelligence and…