IT lexicon Security Mirai botnet

Mirai botnet

Security På svenska → Updated: 2026-05-24

Botnet that hijacked IoT devices (security cameras, routers) via default passwords. Drove historically large DDoS attacks in autumn 2016.

Paras Jha + Josiah White + Dalton Norman behind it (convicted 2017). Mirai scanned the internet for telnet with default passwords (admin/admin, root/root). Major attacks: Brian Krebs's blog (September 2016, 620 Gbps), OVH (1 Tbps), Dyn (October 2016 — took out Twitter, Reddit, Spotify, GitHub on the US east coast). The source code leaked → thousands of variants ("Mirai variants") still active. Drove IoT security legislation globally.

← Back to the lexicon