Lnbot: A covert hybrid botnet on bitcoin lightning network for fun and profit Book Chapter

Kurt, A, Erdin, E, Cebe, M et al. (2020). Lnbot: A covert hybrid botnet on bitcoin lightning network for fun and profit . 12309 LNCS 734-755. 10.1007/978-3-030-59013-0_36

cited authors

  • Kurt, A; Erdin, E; Cebe, M; Akkaya, K; Uluagac, AS


  • While various covert botnets were proposed in the past, they still lack complete anonymization for their servers/botmasters or suffer from slow communication between the botmaster and the bots. In this paper, we propose a new generation hybrid botnet that covertly and efficiently communicates over Bitcoin Lightning Network (LN), called LNBot. LN is a payment channel network operating on top of Bitcoin network for faster Bitcoin transactions with negligible fees. Exploiting various anonymity features of LN, we designed a scalable two-layer botnet which completely anonymize the identity of the botmaster. In the first layer, the botmaster sends commands anonymously to the C&C servers through LN transactions. Specifically, LNBot allows botmaster’s commands to be sent in the form of surreptitious multihop LN payments, where the commands are encoded with ASCII or Huffman encoding to provide covert communications. In the second layer, C&C servers further relay those commands to the bots they control in their mini-botnets to launch any type of attacks to victim machines. We implemented a proof-of-concept on the actual LN and extensively analyzed the delay and cost performance of LNBot. Our analysis show that LNBot achieves better scalibility compared to the other similar blockchain botnets with negligible costs. Finally, we also provide and discuss a list of potential countermeasures to detect LNBot activities and minimize its impacts.

publication date

  • January 1, 2020

Digital Object Identifier (DOI)

International Standard Book Number (ISBN) 13

start page

  • 734

end page

  • 755


  • 12309 LNCS