Mirai: how a Minecraft DDoS service broke the internet
By Elias Lankinen11 min read
Ten Years Ago Today
On the morning of September 20, 2016, the website of a lone security journalist went dark under a flood of junk traffic that peaked at around 620 gigabits per second, according to KrebsOnSecurity's own account. That is roughly the equivalent of streaming tens of thousands of HD movies at once, all aimed at a single blog. It was, at the time, one of the largest denial-of-service attacks ever publicly recorded. Akamai, the content-delivery giant that had been shielding the site for free, could not absorb it indefinitely and had to drop Brian Krebs as a customer. The attack was so far beyond the norm that the academic postmortem later called it "among the largest on record." The strangest part was where the firepower came from. Not a government. Not a criminal syndicate with racks of servers. It came from hundreds of thousands of the internet's most forgettable objects: home routers, digital video recorders, and cheap security cameras, quietly conscripted from bedrooms and storefronts around the world. And the people who built the weapon were not spies. They were three young men, and the thing they originally wanted to win was a video game.
This is the story of Mirai, the malware named with the Japanese word for "future." It is a story about how the cheapest devices on the internet became its most dangerous, about a protection racket run out of Minecraft, and about a mistake in thinking that still shapes how we secure the connected world.
A Protection Racket Built on Minecraft
To understand Mirai you first have to understand that Minecraft, the block-building game, is also a business. Popular multiplayer servers, the machines that host thousands of players in shared worlds, can earn their operators tens of thousands of dollars a month through subscriptions and in-game perks. Where there is money, there is sabotage. As IEEE Spectrum documented in its deep account of the case, Minecraft server administrators routinely hire denial-of-service attacks to knock rivals offline, betting that frustrated players will migrate to a server that actually stays up. Paras Jha, a computer science student at Rutgers University from Fanwood, New Jersey, learned both sides of that economy young. He taught himself to code around age twelve, got deep into Minecraft hosting, and eventually founded a company called ProTraf Solutions that sold protection against exactly the kind of attacks that plagued the scene. The business model, per the federal case, had a dark edge: ProTraf could drum up demand for its own services by attacking the servers it hoped to sign as clients, then offering to make the pain stop. It was, as Spectrum put it, "just like a mafia don running a protection racket." Jha did not work alone. Josiah White, eighteen, had already written major portions of an earlier botnet called Qbot; Dalton Norman, nineteen, hunted for the software vulnerabilities the group could exploit. What they needed to dominate the Minecraft-attack market was more raw bandwidth than any competitor. Ordinary hacked PCs were slow to find and quick to get cleaned. So the trio went looking for a bigger, dumber, more numerous kind of victim.
Jha also had a grudge closer to home. Starting in late 2014, someone repeatedly knocked Rutgers's central authentication system offline, right as students scrambled to register for classes. Jha was eventually charged in connection with those attacks on his own university. The through-line from a college registration server to a global outage runs through one insight: the internet was now full of cheap computers nobody was watching.
How Mirai Actually Worked
The "internet of things" is the marketing name for the billions of everyday devices, cameras, routers, thermostats, baby monitors, that now ship with a network connection and a tiny Linux computer inside. The trouble is that many of them ship with the same factory-set username and password, printed in a manual and never changed by the owner. Worse, many leave open a decades-old remote-access service called Telnet, which sends those passwords across the network in plain text.
Mirai's genius was its bluntness. According to the definitive academic study, Understanding the Mirai Botnet, published at the 2017 USENIX Security Symposium by a team of eighteen researchers from Akamai, Cloudflare, Google, and several universities, the malware ran a "rapid, stateless" scan of the internet, firing probes at random addresses to find machines with Telnet open. When it found one, it tried to log in using a hardcoded dictionary of just 62 username and password pairs, a list tuned to consumer gear: root/xc3511, admin/admin, root/888888, and other combinations that shipped by default on cheap electronics.
That first pair, root/xc3511, matters. Security firm Flashpoint traced it to XiongMai Technologies, a Chinese company in Hangzhou that sells camera and DVR components, preloaded with software and default credentials, to dozens of downstream brands that slap their own names on the finished product. One weak password baked in at the component level propagated into countless devices from vendors who never knew they shared a vulnerability. The USENIX team's device census found the botnet dominated by cameras, DVRs, and home routers, with recognizable hardware from vendors like Dahua, Huawei, ZTE, MikroTik, and D-Link.
Once a device fell, Mirai reported it to a control server, which dispatched a separate "loader" program to install the malware for the device's specific chip architecture. Then the freshly infected device did two things at once: it started scanning for new victims, and it waited for orders. Cleverly, Mirai deleted its own downloaded file and hid under a random process name, so a reboot would wipe it, but an unpatched device would simply be reinfected within minutes. It even killed off competing malware and closed the very ports it had crawled in through, to keep rivals out. The growth was explosive. The researchers watched Mirai infect roughly 65,000 devices in its first 20 hours, with a population doubling time of about 76 minutes. It settled into a steady state of 200,000 to 300,000 infected devices, then spiked to a peak of around 600,000 at the end of November 2016. The bots clustered in a few countries with lots of vulnerable hardware: Brazil, Colombia, and Vietnam together accounted for 41.5 percent of infections. Two details reveal the mindset of its authors. Mirai's code carried a hardcoded blacklist of addresses it would never attack, including ranges belonging to the U.S. Department of Defense, the U.S. Postal Service, and General Electric, an attempt to avoid drawing the wrong attention. And despite building in support for traffic-amplification tricks that most professional attackers relied on, only 2.8 percent of Mirai's attacks actually used them. It didn't need to. Sheer numbers were enough.
The Warning Shots
Krebs was the first big target, but not the last. Within days, in late September 2016, the French hosting company OVH was hit even harder. OVH's founder, Octave Klaba, reported on social media that the assault came from a botnet of roughly 145,000 hacked cameras and DVRs and peaked somewhere between 1.1 and 1.5 terabits per second, shattering the previous record. The internet's defenders were now watching a new kind of weapon stress-test itself in public. Then, at the end of September 2016, came the move that turned Mirai from one gang's tool into an epidemic. A user calling themselves Anna-senpai, a name lifted from a character in the anime Shimoneta, posted the complete Mirai source code to Hackforums, an English-language hacking community. In the release note, Anna-senpai bragged of having commanded up to 380,000 bots over Telnet, and framed the leak as a graceful exit:
When I first go in DDoS industry, I wasn't planning on staying in it long. I made my money, there's lots of eyes looking at IOT now, so it's time to GTFO. There was a colder logic underneath. When security researchers or criminals dump their code publicly, they muddy the water: if dozens of copies exist in the wild, it becomes far harder for investigators to argue that any one person is the author. The release worked as intended, and then some. Within days, multiple competing Mirai botnets were fighting over the same pool of vulnerable devices. The USENIX team catalogued the aftermath: over 1,000 distinct malware samples, at least 33 independent botnets run by different operators, and new variants that added device types, updated the password list, and even removed the Department of Defense from the blacklist.
October 21: The Day Half the Web Stuttered
The attack that put Mirai in front of the general public did not target a website at all. It targeted the internet's phone book.
When you type netflix.com, your computer first asks a Domain Name System (DNS) server to translate that name into a numerical address. Dyn was one of the largest managed DNS providers in the United States, quietly answering those lookups for a huge slice of the modern web. On October 21, 2016, a Mirai botnet hit Dyn in three distinct waves: roughly 11:10 to 13:20 UTC, 15:50 to 17:00, and 20:00 to 22:10. Take out the phone book, and it no longer matters that the websites themselves are perfectly healthy. Nobody can find them.
The list of what broke reads like a census of daily internet life: Twitter, Netflix, Spotify, Reddit, GitHub, PayPal, Amazon, and more than a hundred other major platforms became unreachable for waves of users across North America and Europe. Notably, the security firm Flashpoint concluded that this botnet was a different one from the strains that hit Krebs and OVH, further evidence that the leaked code was now in many hands.
Here is where the most durable misconception took hold. Dyn reported that the attack involved malicious traffic from "tens of millions of IP addresses." That phrasing got compressed in headlines into "tens of millions of devices," implying an unimaginably vast army. But the researchers who actually measured Mirai never counted anywhere near that many bots; the population topped out around 600,000, and the specific botnet aimed at Dyn was smaller still. The gap comes from how DNS attacks and network address translation work: a single infected device can appear as many source addresses, and DNS retries multiply the apparent count. The lesson is more unsettling, not less. It did not take tens of millions of machines to stagger the web. It took a few hundred thousand webcams.
What "Broke the Internet" Gets Wrong
Mirai attracts myths, and two are worth puncturing directly.
The first is that a nation-state or an elite crew must have been behind attacks of this scale. The reality, which the researchers stress as the whole point of their paper, is the opposite: Mirai proved that "novice malicious techniques can compromise enough low-end devices to threaten even some of the best-defended targets." There was no zero-day wizardry. There was a 62-line password list and the fact that millions of people never changed admin/admin.
The second myth is that Mirai once knocked an entire country, Liberia, offline in November 2016. The claim spread widely, but Brian Krebs investigated and knocked it down. A Mirai botnet did hammer a single Liberian mobile operator, Lonestar Cell, with an attack exceeding 500 Gbps, but the company had mitigation in place, undersea-cable monitors showed no national downtime, and the dip in traffic that fed the story may have been a local holiday. The attack was real and serious. "The whole country went dark" was not. It is a useful reminder to treat the scariest framing of any cyber incident with suspicion.
The Reckoning
The same crude simplicity that made Mirai so effective also made its authors traceable. The FBI investigation was led, improbably, out of Anchorage by Special Agent Elliott Peterson, whose team followed the control servers and subpoenaed hosting records. Krebs, using his own reporting, publicly named Paras Jha as Anna-senpai in January 2017. The trail held. In December 2017, Jha, White, and Norman pleaded guilty to conspiracy charges for creating and operating Mirai. By then the three had already pivoted from denial-of-service attacks to something quieter and more lucrative: using their botnet for advertising click fraud, generating fake ad clicks that earned them roughly $180,000 worth of bitcoin, far more than the DDoS work ever had. When they were sentenced in September 2018, the Department of Justice asked for no prison time. Instead the three received five years of probation and 2,500 hours of community service, much of it spent helping the FBI on cybercrime cases, work they had already begun, logging close to 1,000 hours before sentencing. It was a striking bet by the government: that these particular offenders were worth more inside the tent than behind bars. Mirai itself never went away. Because the source code is public, variants still circulate, still scanning for the same weak passwords, still assembling botnets from whatever new gadget ships insecure. The deeper response has been slow and structural. California and the United Kingdom have since passed laws banning universal default passwords on connected devices, precisely the flaw Mirai exploited, and the U.S. now runs a voluntary security label program for consumer IoT. Whether any of it moves fast enough is the open question, because the incentives have barely budged. The person who buys a $30 camera does not pay the price when it joins a botnet; some website they have never heard of does. Ten years after a blog went dark, the future Mirai was named for keeps arriving one cheap, unpatched device at a time, and the bill still lands on someone else's doorstep.
Sources
- Manos Antonakakis et al., USENIX Security Symposium, Understanding the Mirai Botnet (2017)
- Brian Krebs, KrebsOnSecurity, Source Code for IoT Botnet 'Mirai' Released (2016)
- Brian Krebs, KrebsOnSecurity, Mirai IoT Botnet Co-Authors Plead Guilty (2017)
- Brian Krebs, KrebsOnSecurity, Did the Mirai Botnet Really Take Liberia Offline? (2016)
- Garrett M. Graff, IEEE Spectrum, The Strange Story of the Teens Behind the Mirai Botnet (2019)
- Wikipedia, DDoS attacks on Dyn (accessed 2026)
- Flashpoint, Mirai Botnet: When Vulnerabilities Travel Downstream (2016)
- Ellen Tannam, Silicon Republic, Mega IoT cyberattack: OVH suffers 1.5Tbps DDoS attack via 145,000 webcams (2016)
- CISA (US-CERT), Heightened DDoS Threat Posed by Mirai and Other Botnets (2016)