
Supervisory Control and Data Acquisition (SCADA) systems constitute the backbone of Critical National Infrastructure (CNI), supporting essential services such as electric power generation and distribution, water treatment, oil and gas operations, and transportation systems. As Nigeria accelerates the digitization and interconnection of its industrial control systems to improve efficiency and operational visibility, these environments have become increasingly exposed to sophisticated cyber threats. Among the most significant of these threats are botnet-driven attacks, which exploit legacy protocols, weak authentication mechanisms, and limited security monitoring capabilities typical of many SCADA deployments. This study presents a comprehensive analysis of botnet activities targeting SCADA systems within the context of Nigeria’s critical infrastructure. It examines the architecture, command-and-control mechanisms, propagation techniques, and attack objectives of modern botnets that pose risks to industrial control environments. Using a combination of simulated SCADA network environments and empirical analysis of publicly available global botnet datasets, the research identifies prevalent attack vectors, traffic patterns, and system vulnerabilities relevant to Nigerian CNI. Particular attention is given to distributed denial-of-service (DDoS) attacks, reconnaissance and lateral movement behaviours, and malware-driven manipulation of control commands. Building on these findings, the paper proposes a context-aware botnet analytics framework tailored to SCADA systems in developing economies. The framework integrates machine learning–based traffic classification, anomaly detection techniques, and external threat intelligence feeds to enable early detection of botnet activity and support timely mitigation. By emphasizing low-latency monitoring, explainability, and adaptability to resource-constrained environments, the proposed approach addresses both technical and institutional challenges faced by Nigerian infrastructure operators. The study contributes to cybersecurity research by providing empirical insights into botnet threats against SCADA systems and by offering a practical detection and mitigation framework aligned with Nigeria’s critical infrastructure realities. The findings are intended to inform policymakers, infrastructure operators, and cybersecurity practitioners, while also supporting the development of more resilient and proactive cyber defense strategies for national infrastructure protection.