On October 21, 2016, large portions of the internet became unreachable. Twitter, Reddit, Netflix, GitHub, Spotify, Airbnb, CNN, the New York Times, and hundreds of other major sites went offline or became inaccessible to users in the United States and Europe. The cause was a distributed denial-of-service attack against Dyn, a DNS infrastructure provider. Dyn's systems were overwhelmed by traffic. Because millions of websites rely on Dyn to resolve their domain names to IP addresses, when Dyn failed, so did the sites it served.
The attack traffic came from Mirai - a botnet consisting not of compromised computers but of compromised consumer IoT devices: home routers, IP cameras, baby monitors, and digital video recorders. Mirai had been released as open source three weeks earlier by its creator, who hoped that releasing the source code publicly would make it harder for law enforcement to attribute the attack to him specifically. The strategy partially worked and partially failed. The attacker - a Rutgers student named Paras Jha - was eventually identified and pled guilty, but not before Mirai had spawned dozens of variants operated by other parties and demonstrated that the insecure IoT device ecosystem represented a globally distributed attack platform waiting to be used.
How Mirai Worked
Mirai was architecturally simple and devastatingly effective. The botnet propagated by scanning the internet for devices running Telnet on ports 23 and 2323 and attempting login with a hardcoded list of 62 default username/password combinations - combinations like admin/admin, admin/password, root/root, and the factory defaults of specific popular device manufacturers. The vast majority of consumer IoT devices at the time shipped with these default credentials and with no mechanism to prompt users to change them. Many users never knew their camera or router had a Telnet interface, let alone a default password.
When Mirai successfully logged into a device, it checked whether it was already infected (by looking for specific process names), killed any competing malware, loaded the Mirai payload into memory from a download server, and enrolled the device in the botnet. The malware ran entirely in memory on some devices, making it harder to detect but vulnerable to power cycles - rebooting an infected device cleared the infection, though without password changes, the device would likely be reinfected within minutes of going back online.
The Mirai C2 infrastructure directed bots to generate DDoS attack traffic: UDP floods, SYN floods, and DNS query floods. For the Dyn attack, the traffic was DNS queries - each bot sent large volumes of DNS lookup requests to Dyn's servers. With hundreds of thousands of bots generating traffic simultaneously, the aggregate bandwidth overwhelmed Dyn's infrastructure even though each individual device was a low-bandwidth consumer product. Peak traffic during the Dyn attack reached approximately 1.2 Tbps - at the time, one of the largest DDoS attacks ever recorded.
The Dyn Attack and Who Did It
The October 21 Dyn attack was actually the third major Mirai attack. Two weeks earlier, Brian Krebs's security journalism site KrebsOnSecurity had been hit with a 620 Gbps Mirai attack - at the time the largest DDoS ever. A week after that, French hosting provider OVH was hit with approximately 1 Tbps of Mirai traffic. Both attacks were attributed to the same Mirai C2 infrastructure operated by Paras Jha and two collaborators, Josiah White and Dalton Norman.
The trio had originally built Mirai as a tool for competitive gaming - specifically, to DDoS rival Minecraft servers. Gaming DDoS was a large and lucrative market; server operators paid for DDoS protection, and competitors paid for DDoS attacks. Jha and his collaborators ran a DDoS-for-hire service called "ProTraf Solutions" and used Mirai to conduct attacks on behalf of customers. The KrebsOnSecurity attack was retaliation for Krebs's reporting on DDoS-for-hire services.
FBI agents began investigating after the KrebsOnSecurity attack. The Dyn attack, which made national news and disrupted a huge portion of the US internet, accelerated the investigation. Despite the complexity of the botnet, investigators were able to trace the infrastructure back to Jha through analysis of Mirai C2 traffic, domain registration patterns, and forum posting history. Jha had posted extensively on HackForums over years, and the Anna-senpai account had a traceable pattern of activity. All three were identified, and all three cooperated with the FBI - they were reportedly used as technical consultants to help the FBI investigate other cybercriminals while their own cases progressed. Jha, White, and Norman pled guilty in 2017 and received sentences of probation (no prison time), community service, and restitution due to their cooperation.
The DNS Single-Point-of-Failure Problem
The Dyn attack also exposed a concentration risk in internet infrastructure. DNS is a foundational service - without it, domain names don't resolve to IP addresses and the web doesn't work. Dyn was one of the major managed DNS providers, and many large websites had outsourced their DNS to Dyn without maintaining their own authoritative DNS capacity. When Dyn was knocked offline, these sites had no fallback.
After the attack, major websites significantly diversified their DNS providers, maintaining multiple authoritative DNS hosts so that if one was DDoSed, others could still serve requests. Anycast DNS routing, already common among large providers, became more widely adopted: rather than routing all DNS queries to a central data center, anycast distributes traffic across dozens of geographically distributed nodes, making it much harder to overwhelm all of them simultaneously. Cloudflare, which acquired Dyn's DNS infrastructure in 2016, built its DNS service on an anycast architecture with hundreds of points of presence globally, specifically designed to absorb DDoS traffic that would have been catastrophic for a centralized DNS provider.