On October 21, 2016, large portions of the internet became unreachable. Twitter, Reddit, Netflix, GitHub, Spotify, Airbnb, CNN, the New York Times, and hundreds of other major sites went offline or became inaccessible to users in the United States and Europe. The cause was a distributed denial-of-service attack against Dyn, a DNS infrastructure provider. Dyn's systems were overwhelmed by traffic. Because millions of websites rely on Dyn to resolve their domain names to IP addresses, when Dyn failed, so did the sites it served.

The attack traffic came from Mirai - a botnet consisting not of compromised computers but of compromised consumer IoT devices: home routers, IP cameras, baby monitors, and digital video recorders. Mirai had been released as open source three weeks earlier by its creator, who hoped that releasing the source code publicly would make it harder for law enforcement to attribute the attack to him specifically. The strategy partially worked and partially failed. The attacker - a Rutgers student named Paras Jha - was eventually identified and pled guilty, but not before Mirai had spawned dozens of variants operated by other parties and demonstrated that the insecure IoT device ecosystem represented a globally distributed attack platform waiting to be used.

How Mirai Worked

Mirai was architecturally simple and devastatingly effective. The botnet propagated by scanning the internet for devices running Telnet on ports 23 and 2323 and attempting login with a hardcoded list of 62 default username/password combinations - combinations like admin/admin, admin/password, root/root, and the factory defaults of specific popular device manufacturers. The vast majority of consumer IoT devices at the time shipped with these default credentials and with no mechanism to prompt users to change them. Many users never knew their camera or router had a Telnet interface, let alone a default password.

When Mirai successfully logged into a device, it checked whether it was already infected (by looking for specific process names), killed any competing malware, loaded the Mirai payload into memory from a download server, and enrolled the device in the botnet. The malware ran entirely in memory on some devices, making it harder to detect but vulnerable to power cycles - rebooting an infected device cleared the infection, though without password changes, the device would likely be reinfected within minutes of going back online.

The Mirai C2 infrastructure directed bots to generate DDoS attack traffic: UDP floods, SYN floods, and DNS query floods. For the Dyn attack, the traffic was DNS queries - each bot sent large volumes of DNS lookup requests to Dyn's servers. With hundreds of thousands of bots generating traffic simultaneously, the aggregate bandwidth overwhelmed Dyn's infrastructure even though each individual device was a low-bandwidth consumer product. Peak traffic during the Dyn attack reached approximately 1.2 Tbps - at the time, one of the largest DDoS attacks ever recorded.

[TECHNICAL NOTE]
Mirai's source code, published to HackForums on September 30, 2016 under the username "Anna-senpai," revealed the botnet's full architecture: a scanner module (separate binary that scanned for vulnerable devices and reported back), a loader module (handled infection of newly discovered devices), a C2 server (botnet command), and the bot binary itself (loaded onto compromised devices). The 62 default credential pairs were hardcoded in the bot; attempts to authenticate with these credentials over Telnet were the entire propagation mechanism. There was no exploit, no vulnerability - just default passwords that millions of users never changed. Post-release, researchers identified hundreds of Mirai variants. The Qbot, Okiru, Satori, and JenX variants followed within months. The Mirai source code accelerated IoT botnet development by years - any attacker with basic knowledge could compile and operate a Mirai variant with minimal modification. The lasting security impact was the recognition that consumer IoT devices, shipped with default credentials and no update mechanism, constituted a globally distributed insecure computing infrastructure that could be weaponized by any sufficiently motivated attacker.

The Dyn Attack and Who Did It

The October 21 Dyn attack was actually the third major Mirai attack. Two weeks earlier, Brian Krebs's security journalism site KrebsOnSecurity had been hit with a 620 Gbps Mirai attack - at the time the largest DDoS ever. A week after that, French hosting provider OVH was hit with approximately 1 Tbps of Mirai traffic. Both attacks were attributed to the same Mirai C2 infrastructure operated by Paras Jha and two collaborators, Josiah White and Dalton Norman.

The trio had originally built Mirai as a tool for competitive gaming - specifically, to DDoS rival Minecraft servers. Gaming DDoS was a large and lucrative market; server operators paid for DDoS protection, and competitors paid for DDoS attacks. Jha and his collaborators ran a DDoS-for-hire service called "ProTraf Solutions" and used Mirai to conduct attacks on behalf of customers. The KrebsOnSecurity attack was retaliation for Krebs's reporting on DDoS-for-hire services.

FBI agents began investigating after the KrebsOnSecurity attack. The Dyn attack, which made national news and disrupted a huge portion of the US internet, accelerated the investigation. Despite the complexity of the botnet, investigators were able to trace the infrastructure back to Jha through analysis of Mirai C2 traffic, domain registration patterns, and forum posting history. Jha had posted extensively on HackForums over years, and the Anna-senpai account had a traceable pattern of activity. All three were identified, and all three cooperated with the FBI - they were reportedly used as technical consultants to help the FBI investigate other cybercriminals while their own cases progressed. Jha, White, and Norman pled guilty in 2017 and received sentences of probation (no prison time), community service, and restitution due to their cooperation.

[WARNING]
The Mirai botnet's enduring significance is the question it asked and never finished answering: who is responsible for securing consumer IoT devices? At the time of the Dyn attack, the devices used to build Mirai were legal products sold by legitimate manufacturers. The manufacturers shipped them with default passwords and no update mechanism and had no liability for the DDoS attacks their devices participated in. The users of those devices were largely unaware of the security problem. Regulations requiring IoT security baseline practices - specifically, prohibition of default credentials and mandatory security update mechanisms - began to be adopted in the UK (Product Security and Telecommunications Infrastructure Act 2022), EU (Cyber Resilience Act 2024), and California (SB-327, 2018). The US began moving toward similar federal requirements. The Mirai incident was the catalyst for this regulatory shift: it demonstrated concretely that the absence of IoT security requirements created risk not just for device owners but for the entire internet infrastructure.

The DNS Single-Point-of-Failure Problem

The Dyn attack also exposed a concentration risk in internet infrastructure. DNS is a foundational service - without it, domain names don't resolve to IP addresses and the web doesn't work. Dyn was one of the major managed DNS providers, and many large websites had outsourced their DNS to Dyn without maintaining their own authoritative DNS capacity. When Dyn was knocked offline, these sites had no fallback.

After the attack, major websites significantly diversified their DNS providers, maintaining multiple authoritative DNS hosts so that if one was DDoSed, others could still serve requests. Anycast DNS routing, already common among large providers, became more widely adopted: rather than routing all DNS queries to a central data center, anycast distributes traffic across dozens of geographically distributed nodes, making it much harder to overwhelm all of them simultaneously. Cloudflare, which acquired Dyn's DNS infrastructure in 2016, built its DNS service on an anycast architecture with hundreds of points of presence globally, specifically designed to absorb DDoS traffic that would have been catastrophic for a centralized DNS provider.

[IOC]
Mirai botnet indicators: the original Mirai bot binary was ELF format compiled for multiple CPU architectures (x86, ARM, MIPS variants) to support the diverse processor landscape in IoT devices. File names varied but common staging names included "mirai.arm7", "mirai.mips", and variants. The Mirai scanner operated on TCP port 23 and 2323. The 62 default credential pairs are publicly documented in the released source code and include manufacturer-specific defaults for Dahua cameras, Huawei routers, ZTE devices, and other common consumer equipment. C2 communication used a custom binary protocol over TCP. Infected devices could be identified by unusual outbound traffic patterns to scanner targets (random IP ranges on port 23) and by outbound connections to Mirai C2 IPs (varied by variant). The simplest detection is scanning your own network for devices with open Telnet ports and attempting default credential login - if it succeeds, you have a Mirai-vulnerable device. IoT device security baseline: disable Telnet, change default credentials, update firmware, place on isolated network segment. The Mirai source code remains available via GitHub and various archives and continues to be used as the basis for new IoT botnet variants.