The Mirai malware turned insecure internet-connected devices into massive DDoS botnets that powered some of the largest attacks publicly reported, including floods against OVH, KrebsOnSecurity, and DNS provider Dyn. The botnet spread by logging into exposed IoT devices such as cameras, DVRs, routers, and gateways with hardcoded or default credentials, and defenders later warned that products including certain Sierra Wireless AirLink gateways could be conscripted if factory passwords were left unchanged. After the malware’s source code was released publicly under the alias "Anna-senpai", multiple actors were able to build copycat botnets, increasing attack volume and complicating attribution.
The Dyn attack disrupted access to major online services including Twitter, Spotify, Reddit, GitHub, Airbnb, Shopify, SoundCloud, and The New York Times, with Dyn describing a highly distributed, adaptive campaign delivered in several waves from vast numbers of IP addresses. Investigative reporting tied Mirai’s origins to the DDoS-for-hire and Minecraft-hosting ecosystem and presented evidence linking the Anna-senpai persona to Paras Jha and associates, while later reporting showed Mirai variants continued launching attacks long after the original incidents. Researchers identified limited countermeasures, including crashing some bots via a flaw in Mirai’s HTTP flood code and traceback methods for DNS amplification traffic, but the broader risk persisted because vulnerable IoT devices remained widely deployed and malware authors could quickly adapt.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
An investigative report published in January 2017 tied the Mirai author alias 'Anna-Senpai' to Paras Jha and linked Mirai's development and use to the DDoS-for-hire and Minecraft server protection ecosystem. The report also connected the alias cluster to extortion, anti-competitive attacks, and abuse campaigns against rival botnets, while Jha denied writing Mirai.
In late October 2016, sustained DDoS attacks reportedly using the Mirai botnet targeted two companies that co-owned Liberia's only fiber connection, severely disrupting the country's internet access. Security researchers said the attacks exceeded 500-600 Gbps, showing that Mirai operators could significantly affect a nation's connectivity infrastructure.
On October 22 and again on October 24, 2016, Singapore ISP StarHub suffered DNS-service disruptions that it traced to malware-infected IoT devices belonging to home broadband subscribers. The specific malware was not publicly identified.
During the Dyn outage response, Dyn and outside investigators said some of the malicious traffic came from Mirai-infected IoT devices. Flashpoint reported the infrastructure involved was Mirai-linked and distinct from the botnets previously used against Brian Krebs and OVH, while U.S. authorities including DHS began investigating.
On October 21, 2016, DNS provider Dyn was hit by several waves of DDoS traffic that disrupted access to major sites including Twitter, Spotify, Reddit, GitHub, Airbnb, and the New York Times. Dyn described the attack as highly distributed and adaptive, with U.S. users especially affected.
Sierra Wireless alerted customers that Mirai was compromising certain AirLink gateway models that still used factory-default credentials. ICS-CERT said the issue stemmed from weak configuration rather than a product flaw, and advised changing credentials and rebooting infected devices.
After Mirai had already been used in major attacks, its source code was publicly released on GitHub by the actor using the alias 'Anna-senpai.' Reporting said the botnet had previously controlled hundreds of thousands of IoT devices and that the release likely complicated attribution and enabled copycat botnets.
In late September 2016, hosting provider OVH was struck by record-breaking DDoS attacks peaking near 1 Tbps. Reports said the traffic came from a botnet of more than 152,000 hacked IoT devices such as cameras and DVRs.
In September 2016, KrebsOnSecurity was hit by a record 620 Gbps DDoS attack that forced Akamai to stop providing protection because of the attack's scale and cost. Reporting attributed the assault largely to a botnet of compromised IoT devices such as routers, cameras, and DVRs, and linked it to retaliation after coverage of the vDOS service.
By May 2026, defenders had publicized two notable countermeasures: a stack buffer overflow in Mirai's HTTP flood code that could crash attacking bots, and a CISPA-developed traceback method for identifying the origins of DNS amplification attacks. Reporting noted these measures could help mitigation but were not complete solutions because Mirai variants could be patched and vulnerable IoT devices remained widespread.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
24 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourceflashpoint-intel.com
Open sourcehelpnetsecurity.com
Open sourcecsoonline.com
Open sourcethehackernews.com
Open sourcekrebsonsecurity.com
Open sourcekrebsonsecurity.com
Open sourceblog.sucuri.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.