Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructuredefault-credential-exposureoperational-disruptionembedded-device-vulnerability

Mirai IoT Botnet Fueled Record DDoS Attacks and Widespread Internet Outages

Updated 29d agoFirst seen May 25, 202624 sources

The Mirai malware turned insecure internet-connected devices into massive DDoS botnets that powered some of the largest attacks publicly reported, including floods against OVH, KrebsOnSecurity, and DNS provider Dyn. The botnet spread by logging into exposed IoT devices such as cameras, DVRs, routers, and gateways with hardcoded or default credentials, and defenders later warned that products including certain Sierra Wireless AirLink gateways could be conscripted if factory passwords were left unchanged. After the malware’s source code was released publicly under the alias "Anna-senpai", multiple actors were able to build copycat botnets, increasing attack volume and complicating attribution.

The Dyn attack disrupted access to major online services including Twitter, Spotify, Reddit, GitHub, Airbnb, Shopify, SoundCloud, and The New York Times, with Dyn describing a highly distributed, adaptive campaign delivered in several waves from vast numbers of IP addresses. Investigative reporting tied Mirai’s origins to the DDoS-for-hire and Minecraft-hosting ecosystem and presented evidence linking the Anna-senpai persona to Paras Jha and associates, while later reporting showed Mirai variants continued launching attacks long after the original incidents. Researchers identified limited countermeasures, including crashing some bots via a flaw in Mirai’s HTTP flood code and traceback methods for DNS amplification traffic, but the broader risk persisted because vulnerable IoT devices remained widely deployed and malware authors could quickly adapt.

Share:
Mirai IoT Botnet Fueled Record DDoS Attacks and Widespread Internet Outages
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Jan 18, 20179y ago

Krebs report links 'Anna-Senpai' identity to Paras Jha and Mirai ecosystem

An investigative report published in January 2017 tied the Mirai author alias 'Anna-Senpai' to Paras Jha and linked Mirai's development and use to the DDoS-for-hire and Minecraft server protection ecosystem. The report also connected the alias cluster to extortion, anti-competitive attacks, and abuse campaigns against rival botnets, while Jha denied writing Mirai.

Oct 31, 201610y ago

Mirai-linked DDoS attacks disrupt Liberia's national internet connectivity

In late October 2016, sustained DDoS attacks reportedly using the Mirai botnet targeted two companies that co-owned Liberia's only fiber connection, severely disrupting the country's internet access. Security researchers said the attacks exceeded 500-600 Gbps, showing that Mirai operators could significantly affect a nation's connectivity infrastructure.

Massive cyber-attack grinds Liberia's internet to a halt | Hacking | The Guardian
Oct 22, 201610y ago

StarHub experiences DNS disruptions traced to infected IoT devices

On October 22 and again on October 24, 2016, Singapore ISP StarHub suffered DNS-service disruptions that it traced to malware-infected IoT devices belonging to home broadband subscribers. The specific malware was not publicly identified.

Oct 21, 201610y ago

Dyn and investigators link attack traffic to Mirai botnets

During the Dyn outage response, Dyn and outside investigators said some of the malicious traffic came from Mirai-infected IoT devices. Flashpoint reported the infrastructure involved was Mirai-linked and distinct from the botnets previously used against Brian Krebs and OVH, while U.S. authorities including DHS began investigating.

Dyn suffers multi-wave DDoS attack causing major internet outages

On October 21, 2016, DNS provider Dyn was hit by several waves of DDoS traffic that disrupted access to major sites including Twitter, Spotify, Reddit, GitHub, Airbnb, and the New York Times. Dyn described the attack as highly distributed and adaptive, with U.S. users especially affected.

Oct 17, 201610y ago

Sierra Wireless warns Mirai is infecting default-configured gateways

Sierra Wireless alerted customers that Mirai was compromising certain AirLink gateway models that still used factory-default credentials. ICS-CERT said the issue stemmed from weak configuration rather than a product flaw, and advised changing credentials and rebooting infected devices.

Sep 30, 201610y ago

Mirai source code released publicly by 'Anna-senpai'

After Mirai had already been used in major attacks, its source code was publicly released on GitHub by the actor using the alias 'Anna-senpai.' Reporting said the botnet had previously controlled hundreds of thousands of IoT devices and that the release likely complicated attribution and enabled copycat botnets.

Sep 28, 201610y ago

OVH hit by record DDoS from 152,000 compromised IoT devices

In late September 2016, hosting provider OVH was struck by record-breaking DDoS attacks peaking near 1 Tbps. Reports said the traffic came from a botnet of more than 152,000 hacked IoT devices such as cameras and DVRs.

Sep 25, 201610y ago

KrebsOnSecurity knocked offline by 620 Gbps IoT botnet DDoS

In September 2016, KrebsOnSecurity was hit by a record 620 Gbps DDoS attack that forced Akamai to stop providing protection because of the attack's scale and cost. Reporting attributed the assault largely to a botnet of compromised IoT devices such as routers, cameras, and DVRs, and linked it to retaliation after coverage of the vDOS service.

The Democratization of Censorship - Krebs on Security

Researchers highlight defensive techniques against Mirai-driven attacks

By May 2026, defenders had publicized two notable countermeasures: a stack buffer overflow in Mirai's HTTP flood code that could crash attacking bots, and a CISPA-developed traceback method for identifying the origins of DNS amplification attacks. Reporting noted these measures could help mitigation but were not complete solutions because Mirai variants could be patched and vulnerable IoT devices remained widespread.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Mirai IoT Botnet Fueled Record DDoS Attacks and Widespread Internet Outages | Mallory