How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
The devices that knocked Twitter, Netflix and Reddit offline on October 21, 2016 were not cracked by clever code. Mostly they were cameras, video recorders and routers still using the passwords they shipped with.[4][6] This case file covers how the Mirai botnet was built and spread, how its three young authors ended up working with the FBI, and the one control that would have starved it.
What happened
In the summer and fall of 2016, three men in their early 20s, Paras Jha, Josiah White and Dalton Norman, built a piece of malware they called Mirai. It searched the internet for small connected gadgets such as security cameras, video recorders and home routers, took them over, and pooled them into a botnet, a network of hijacked machines that obey one controller. At its peak it held hundreds of thousands of devices.[1][2]
The group used the botnet to flood targets with junk traffic, an attack called distributed denial of service, or DDoS, and to earn money from advertising click fraud.[1] One of the first known victims was a well-known security journalist's website, hit with about 620 gigabits per second of traffic.[1][4]
That same fall, Jha posted Mirai's source code on a hacker forum under the name "Anna-senpai," letting anyone run their own copy.[2][3][4] Prosecutors later called the release one of the most damaging things the group did, because the copies outlived the originals.[2]
On Friday, October 21, 2016, Mirai-infected devices hit Dyn, a company that ran the internet's address lookup service for many large websites. Dyn engineers began fighting the flood around 7:10 a.m. Eastern time, and a second wave followed later in the day. Twitter, Netflix, Reddit, Spotify, Amazon and others were hard to reach for parts of the day, with major services back by late afternoon.[5][6]
How it worked
Many cheap internet-connected devices came from the factory with a built-in administrator login that was the same on every unit and easy to guess. Owners rarely changed it, and some devices made that hard to do. Mirai carried a short list of these factory logins and simply tried them on any device it could reach from the internet. When one worked, the device joined the botnet.[4][6][7]
Nothing on the hijacked device looked broken. The camera still recorded and the router still routed. The owner usually had no idea the device was also firing traffic at strangers.
The Dyn attack showed why a single weak point in the internet's plumbing matters. Dyn's servers translate a website name into the numeric address a browser needs. When Dyn was swamped, the sites themselves were fine, but browsers could not find them. Dyn later said about 100,000 malicious endpoints, mostly running Mirai, took part, and that normal computers retrying failed lookups pushed traffic to 10 to 20 times normal volume, making the attack look far bigger than it was.[5]
How it was caught
In January 2017 a security journalist publicly identified Jha and White as the likely authors.[1] In December 2017 all three pleaded guilty in federal court in Alaska to conspiracy to violate the Computer Fraud and Abuse Act for operating Mirai. Jha also pleaded guilty separately to a string of attacks on the network of Rutgers University.[1][3] The Justice Department's case covered running the botnet, not the Dyn attack, which was carried out using a copy of the leaked code.
What it cost
In September 2018 each of the three was sentenced to 5 years of probation and 2,500 hours of community service, and together they were ordered to pay $127,000 in restitution.[2][3] The unusually light sentences reflected what court papers called extraordinary cooperation: the men had been helping the FBI with other cybercrime cases, and continuing that work was part of the deal.[2][3] In the separate Rutgers case, Jha was ordered to pay $8.6 million in restitution and serve a term of home confinement.[8]
The bill for everyone else was harder to total. Hangzhou Xiongmai, a Chinese maker whose circuit boards sat inside many brands of webcam and recorder, recalled cameras using its parts and said that owners who never changed default passwords were part of the problem.[7] Mirai copies kept circulating for years afterward.[2]
The missing control
The missing control: forcing default passwords to be changed. The devices shipped with a shared factory login, and nothing required anyone to replace it before the device went online.
Mirai did not break encryption or find some rare software flaw. It walked in through doors that were never locked. If each device had come with a unique password, or refused to connect until the owner set one, the list of factory logins would have opened almost nothing, and the botnet would have been a fraction of its size. The same fix works at the other end: a business that changes every default login the day a device arrives is not part of anyone's botnet.
What to do in your business
- List everything with a login. Walk the office and write down every camera, video recorder, router, printer, smart TV and door system that connects to the internet or your network.
- Change every factory password. Replace each default login with a unique, long password stored in a password manager, and do it before a new device goes into service.
- Turn off outside access you do not need. Many cameras and recorders allow remote viewing by default. If nobody watches from home, switch it off, or use the maker's secure app instead of an open connection.
- Buy devices that force a new password. When choosing cameras or routers, prefer ones that make you set a password on first setup and still receive security updates.
- Put gadgets on their own network. Keep cameras and smart devices on a separate guest or device network so a hijacked one cannot reach your computers or files.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- How the MGM Resorts cyberattack happened: the help desk call that cost $100 million
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- TechTarget: Mirai creators and operators plead guilty to federal charges
- Alaska's News Source: Mirai botmasters sentenced in District of Alaska federal court
- Security Affairs: Mirai authors avoid jail by helping US authorities in other investigations
- TechCrunch: Hackers release source code for a powerful DDoS app called Mirai
- Help Net Security: Dyn DDoS attack post-mortem
- Forbes: Hacked cameras behind the Dyn attack that hit Twitter and Netflix
- TechCrunch: Webcams involved in the Dyn DDoS attack recalled
- BankInfoSecurity: Mirai co-author gets house arrest, $8.6 million fine