onlinesyscfg.research
utc
syscfg://research
home/research/mirai-botnet
PublishedMalware Analysis

Mirai: How Three College Students Broke the Internet With Default Passwords

2026-08-09-17 min read
#mirai#botnet#iot#ddos#dyn#paras-jha#default-credentials#telnet

On October 21, 2016, large parts of the internet stopped working. Twitter went down. Netflix was unavailable. Reddit was unreachable. GitHub, Spotify, CNN, the New York Times - all offline or badly degraded. The cause was not a sophisticated state-sponsored intrusion or a vulnerability in the affected services. It was a DDoS attack against a DNS provider - Dyn - launched by an army of compromised IP cameras, home routers, and baby monitors.

The botnet was called Mirai. At its peak it controlled roughly 600,000 devices. It had been built by three college students in their spare time - not to disrupt the internet, but to gain advantage in a Minecraft hosting business dispute. And it had already been pointed at a security blogger's website weeks earlier, setting a record for the largest DDoS attack in history. A record that held for less than a month.

◈ interactive artifact
Mirai Botnet C2 Simulator
Simulate the Mirai infection cycle: scanning IPv4 space for default-credential IoT devices, building the botnet, and launching DDoS attacks.

//The Architecture of Mirai

Mirai's design was straightforward. A scanner ran on infected devices, continuously probing random IP addresses for open Telnet ports (23 and 2323). When it found a responsive device, it tried a list of 62 default username/password combinations - the factory credentials that manufacturers ship on IoT devices and that most users never change. Credentials like admin:admin, root:xc3511 (a common Chinese IP camera default), and the memorably specific admin:7ujMko0vizxv.

If a combination worked, the device reported back to a loader server, which logged in and downloaded the Mirai binary appropriate for the device's architecture - MIPS, ARM, x86, or several others. The infected device then began its own scanning loop, and reported to the command-and-control infrastructure.

The bot code was deliberately minimal. Mirai did not attempt to maintain persistence through reboots in the traditional sense - it stored itself only in memory, so a reboot would clean an infected device. But the scanning was fast enough that devices were re-infected within seconds of rebooting in many cases. The botnet self-healed continuously.

[INFO]
Mirai also included code to block competing malware from infecting the devices it had compromised. It would firewall off Telnet access after taking control and kill processes associated with other known IoT botnets. Device resources were a finite commodity, and Mirai was aggressive about protecting them.

//The Authors

Paras Jha was a freshman at Rutgers University in 2016. He had been involved in DDoS attacks against Rutgers's own network - knocking out the authentication system repeatedly - and was a key figure in a competitive DDoS-for-hire market focused on disrupting Minecraft hosting competitors. His co-conspirators were Josiah White and Dalton Norman, both also teenagers or barely out of their teens at the time.

The three had built Mirai not to take down global DNS infrastructure or demonstrate a political point - they wanted to knock competitors' Minecraft servers offline. The scale of what they had built significantly exceeded what they needed for that purpose. When the Dyn attack happened in October 2016, it was not launched directly by Jha, White, or Norman. They had released the Mirai source code publicly on the Hackforums underground forum weeks earlier, and a third-party actor had used it to attack Dyn.

The source code release was partly an attempt to muddy the waters - if everyone had Mirai, attribution became harder. It had the opposite effect in terms of scale: within weeks, dozens of Mirai variants had spawned, each building on the original and adapting it for different purposes and vulnerabilities.

//The Krebs Attack

On September 20, 2016, security journalist Brian Krebs's website - KrebsOnSecurity.com - was hit with a DDoS attack peaking at 620 Gbps. At the time, this was the largest publicly disclosed DDoS attack in history. Akamai, which had been providing Krebs with free DDoS protection as a public service, dropped him as a client because the attack was too large to absorb economically.

The attack was believed to be retaliation for Krebs's investigative reporting on DDoS-for-hire services. The technical signature matched what would later be identified as Mirai. Google's Project Shield picked up the protection of KrebsOnSecurity shortly after - the attack had the ironic effect of bringing Krebs more protection than he had before.

//The Dyn Attack

On October 21, 2016, Dyn DNS was hit with multiple waves of DDoS traffic. Dyn provided authoritative DNS for a large fraction of prominent internet services. When Dyn was unable to resolve domain names, services that depended on it became unreachable - not because those services themselves were attacked, but because users could not look up their IP addresses.

The attack came in multiple waves throughout the day. Peak traffic was estimated at 1.2 Tbps - nearly double the record set weeks earlier against Krebs. An estimated 100,000 devices participated in the attack against Dyn, a fraction of the overall Mirai botnet. The affected geography was primarily the eastern United States, where Dyn had its largest presence.

[WARNING]
The Dyn attack affected services including Twitter, Netflix, Reddit, GitHub, Spotify, CNN, PayPal, and dozens of others. For many users on the US East Coast, the internet appeared to simply stop working for hours. The attack was a demonstration that attacking DNS infrastructure could be more effective than attacking individual services.

//The Liberia Campaign

In the weeks after the Dyn attack, another Mirai variant was used to repeatedly DDoS the internet infrastructure of an entire country. Liberia had a single submarine cable connection to the internet, managed by a company called Lonestar Cell. Repeated DDoS attacks against this infrastructure intermittently took the country's entire internet connectivity offline.

This was the first documented case of a country being effectively disconnected from the internet via DDoS - not by attacking its government, but by attacking its commercial connectivity infrastructure. The attacks were brief and the connectivity recovered, but the incident demonstrated that nation-scale disruption was possible with commodity botnet tools.

//Arrest and Fallout

Paras Jha, Josiah White, and Dalton Norman were identified by the FBI and pleaded guilty in December 2017. The investigation was notable for having been conducted relatively quickly - under a year after the Dyn attack - despite the deliberate obfuscation of releasing the source code. The investigators traced the original development to the trio through forum posts, code analysis, and financial flows from the DDoS-for-hire services.

In a somewhat unusual arrangement, all three cooperated extensively with the FBI after arrest. They were sentenced to probation rather than prison time, with the court citing their cooperation and subsequent assistance to the FBI in analysing and tracking other cybercrime operations. Jha separately pleaded guilty to the Rutgers attacks.

The Mirai source code release had lasting consequences that extended far beyond the original authors. Variants proliferated throughout 2017 and 2018: Satori, Okiru, JenX, Masuta, and many others each extended the original with new vulnerabilities, new architectures, or new capabilities. The IoT botnet ecosystem that exists today is built on Mirai's foundations.

//Why It Still Works

The underlying conditions that made Mirai possible have not meaningfully changed. Consumer IoT devices are still shipped with default credentials. Many are still reachable via Telnet. The economics of consumer electronics manufacturing provide no incentive to ship devices with randomised per-device credentials or mandatory setup processes that force password changes.

Regulatory pressure has increased - the UK's Product Security and Telecommunications Infrastructure Act (2022) and California's SB-327 (2020) both require that IoT devices either have unique default credentials or require users to set a password before the device will function. But enforcement is limited, many devices are manufactured outside jurisdictions where these laws apply, and the installed base of vulnerable devices from before these regulations is enormous.

The Numbers

The scale Mirai demonstrated was unprecedented: 600,000 compromised devices, 1.2 Tbps peak DDoS capacity, and enough throughput to take out a country's internet connectivity. All of it was built on the simple observation that most IoT devices shipped with the same credentials from the factory and were never changed by their owners.