EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/cyberattack/mirai-botnet-2016
247/430

File EL-0184CriticalResolvedCyberattack / Distributed Denial of Service (DDoS)

Mirai IoT Botnet / Dyn DDoS Attack

Also filed as Mirai Botnet · Dyn DNS DDoS Attack · IoT Botnet Attack

The Mirai Botnet attack, peaking in September 2016, was one of the most significant DDoS events in history. It leveraged compromised Internet of Things (IoT) devices to generate massive amounts of traffic. The attack targeted Dyn DNS, which served as a critical resolver for major internet services, causing widespread service outages globally.

  • #iot
  • #botnet
  • #ddos
  • #mirai
  • #dyn
  • #2016
Notoriety9/10
Event
20 Sept 2016
Disclosed
20 Sept 2016
Target
Dyn DNS
Actor
Mirai Botnet Operators
Scale
Estimated to be in the range of Terabits per second (Tbps)
Status
Resolved

01Summary

The Mirai Botnet utilized a simple, yet devastating, vulnerability in poorly secured IoT devices, primarily routers and cameras. The botnet operated by scanning the internet for devices with default or weak credentials, exploiting known vulnerabilities to gain control. Once compromised, these devices were enlisted to participate in a massive Distributed Denial of Service (DDoS) attack. The attack specifically targeted Dyn DNS, a major DNS provider, overwhelming its capacity and causing cascading failures across numerous high-profile websites. The sheer volume of traffic, generated by tens of thousands of compromised devices, demonstrated the critical security risks inherent in the rapidly expanding, poorly secured IoT ecosystem. The incident forced major tech companies to reassess their infrastructure resilience and security practices.

02Background

The proliferation of Internet of Things (IoT) devices, many of which were designed with minimal security features and default passwords, created a massive, untapped attack surface. Prior to Mirai, DDoS attacks were often limited in scale or required more sophisticated exploits. Mirai demonstrated that low-cost, ubiquitous consumer electronics could be weaponized into a powerful, decentralized attack platform.

03Key revelations

  1. 01The vulnerability of the rapidly expanding Internet of Things (IoT) sector to weaponization.
  2. 02The critical dependency of major internet services (Twitter, Netflix) on a single DNS provider (Dyn).
  3. 03The effectiveness of simple, low-cost malware in causing global-scale infrastructure failure.

04Technical analysis

The Mirai malware was designed to exploit weak credentials (e.g., 'admin'/'admin') on various IoT devices. It used a simple TCP/IP stack to send SYN flood packets and other high-volume traffic. The botnet architecture was relatively simple, relying on the sheer number of compromised devices (the 'zombies') to achieve massive bandwidth saturation, overwhelming the target's network capacity.

Attack vector
Default or weak credentials (e.g., 'admin'/'admin') on IoT devices, combined with unpatched vulnerabilities.
Attack method
Botnet recruitment (scanning for vulnerable devices) followed by coordinated volumetric DDoS attack.
Initial access
Network Scanning and Exploitation of Default Credentials
Lateral movement
N/A (Devices were compromised individually)
Persistence
Maintaining command and control (C2) connection via compromised devices.
Exfiltration
N/A (The goal was disruption, not data theft)
Tool / malware
Mirai
Malware family
Botnet Malware
Malware type
Botnet / DDoS Generator

Vulnerabilities exploited

  • Default Credentials
  • Weak Authentication

MITRE ATT&CK techniques

  • T1499

05Threat actor

The operators were identified as a group of individuals who sold the Mirai malware and services. Their profile suggests a focus on opportunistic, high-impact criminal activity rather than ideological hacktivism, aiming for maximum disruption and financial leverage.

Aliases

  • Mirai
  • IoT Botnet

MITRE groups

  • T1499

Known members

  • Paras Jha
  • Josiah White
  • Dalton Norman

Attribution sources

  • Security Industry Analysis
  • Government Advisories

06Victims and impact

Additional victims

  • Twitter
  • Netflix
  • Reddit
  • GitHub

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • Network Traffic

Notable documents

  • Dyn DNS Service Status Reports (Sept 2016)

08Financial damage

Damage was primarily measured in lost revenue and service downtime, not direct ransom payments.

09Timeline

  1. 2016-09-20Mirai Botnet begins targeting Dyn DNS, causing initial service disruptions.
  2. 2016-09-21The attack escalates, causing major outages for Twitter, Netflix, and Reddit.
  3. 2016-09-22Mitigation efforts stabilize the DNS infrastructure, marking the peak of the incident.

10Key figures

  • Paras JhaCo-developer/OperatorIndianConvicted/Charged
  • Josiah WhiteCo-developer/OperatorAmericanConvicted/Charged
  • Dalton NormanCo-developer/OperatorAmericanConvicted/Charged

11On the record

The sheer volume of traffic demonstrated the critical security risks inherent in the rapidly expanding, poorly secured IoT ecosystem.

Security Analysts, Post-incident analysis of the Mirai attack.

12Reaction and fallout

Public reaction

The public reaction highlighted a growing awareness of digital infrastructure fragility and the need for better consumer device security. It led to increased media scrutiny of smart home devices and IoT security standards.

Political impact

Governments and regulatory bodies faced pressure to mandate minimum security standards for consumer electronics and critical infrastructure components. This accelerated discussions around 'Internet of Things' regulation.

Geopolitical consequences

The incident underscored the global interconnectedness of modern infrastructure, making critical DNS providers a high-value target for state and non-state actors alike.

13Legal

The operators were eventually identified and faced criminal charges in the US, leading to convictions and significant legal precedents regarding cybercrime.

Prosecutions

  • Paras JhaConvicted
    Charge
    Computer Fraud and Abuse Act violations
    Jurisdiction
    United States
    Sentence
    Imprisonment

Civil lawsuits

  • Class-action lawsuits against IoT manufacturers for lack of security updates.

14Aftermath

Policy changes

  • Increased emphasis on mandatory security updates and patching cycles for IoT devices.
  • Industry best practices for DNS redundancy and DDoS mitigation.

Regulatory changes

  • Increased scrutiny from bodies like the FTC regarding consumer product security.
  • Adoption of stricter security guidelines for critical infrastructure components.

Security improvements

  • Implementation of network segmentation and rate limiting at DNS resolvers.
  • Mandatory change of default credentials for all consumer electronics.

15Significance and legacy

Significance

Mirai is historically significant because it marked the moment the Internet of Things transitioned from a niche technology to a critical, exploitable attack vector. It demonstrated that the weakest link in the digital chain—the unsecured consumer device—could be leveraged to disrupt global, high-value services.

Legacy

The attack spurred the creation of dedicated IoT security standards and increased investment in network resilience. It fundamentally changed how cybersecurity professionals view the attack surface, treating every connected device as a potential point of failure.

16Disclosure and media

Authentication
Technical analysis of malware samples and network traffic logs.

Media partners

  • The New York Times
  • BBC News
  • Reuters

Publishing organisations

  • Security Research Firms
  • Major News Outlets

17Related files

Related events

  • WannaCry Ransomware Attack (2017)

Went on to inspire

  • Botnet attacks targeting industrial control systems (ICS) using similar principles.

18Field notes

  1. 01The Mirai malware was initially designed to target DVRs (Digital Video Recorders) but quickly adapted to a wide range of devices.
  2. 02The attack was one of the first widely publicized examples of a botnet leveraging the sheer volume of consumer-grade, unsecured devices.

19Resolution

The primary mitigation involved increasing the capacity and implementing advanced rate-limiting and filtering techniques at the DNS resolver level, alongside public awareness campaigns urging users to secure their IoT devices.

20Sources

Official documents

  • FBI Cyber Incident Reports (2016)

References

  1. [1]Krebs on Security Blog Posts (2016)
  2. [2]Dyn DNS Status Updates
Fact sheetEL-0184

Dates

Event
20 Sept 2016
Started
20 Sept 2016
Ended
22 Sept 2016
Duration
3 days
Discovered
20 Sept 2016
Disclosed
20 Sept 2016
Resolved
22 Sept 2016
Ongoing
No

Target

Organisation
Dyn, Inc.
Type
Technology Company
Sector
Domain Name System (DNS) / Internet Infrastructure
Country
United States

Actor

Name
Mirai Botnet Operators
Type
Criminal Gang
Motivation
Financial gain, disruption, and demonstrating capability through large-scale attacks.
Attribution
Medium
Status
Convicted
Arrested
Yes
Convicted
Yes
Sentence
Sentenced to prison time (details vary by jurisdiction and specific charge)

Data

Volume
Estimated to be in the range of Terabits per second (Tbps)
Sensitivity
Public
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.