U.S. authorities unsealed guilty pleas from Paras Jha and Josiah White for creating and operating the Mirai botnet, while Dalton Norman admitted participating in a related click-fraud conspiracy. Prosecutors said Mirai compromised vulnerable Internet of Things devices including routers, cameras, and DVRs, growing to more than 300,000 infected systems that were used for distributed denial-of-service attacks, extortion, and botnet rental activity. Jha and White also pleaded guilty to conspiracy to intentionally damage protected computers under 18 U.S.C. 1030(a)(5)(A).
The case tied Mirai to some of the most disruptive DDoS incidents of the period, including the attack on KrebsOnSecurity and the assault on Dyn that interrupted access to major online services. Court documents said the conspirators also redirected the botnet toward ad-click fraud, generating fraudulent traffic that brought in roughly 200 bitcoin, with Norman personally earning more than 30 bitcoin. Research on Mirai has shown how the malware systematically scanned for poorly secured IoT devices and weaponized them at scale, underscoring how weak default security in connected devices enabled one of the internet’s most consequential botnets.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
On October 21, 2016, a Mirai botnet was used in the attack on Dyn. The disruption affected major online services including Twitter, Netflix, and Reddit.
On September 20, 2016, a Mirai botnet attack sourced from more than 175,000 IoT devices struck KrebsOnSecurity. The attack peaked at 620 Gbps and led Akamai to remove the site from its network because of the impact on paying customers.
At the end of September 2016, the Mirai source code was released publicly by its authors. The release led to multiple copycat Mirai botnets competing for vulnerable IoT devices.
An update in the article states that Paras Jha also pleaded guilty in a separate New Jersey case involving DDoS attacks against Rutgers University. No explicit date for that plea is provided in the content.
On Tuesday, the U.S. Department of Justice unsealed guilty pleas from Paras Jha and Josiah White for developing and using Mirai, and from Dalton Norman for participating in a related click-fraud conspiracy. The plea documents said the conspirators also leased botnet access for click fraud and rented it to other cybercriminals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.