September 26, 2026
π‘ Mirai: The Botnet That Used Smart Devices to Break the Internet
What if thousands of cameras, routers, and DVRs in peopleβs homes suddenly became an army controlled by hackers?

By BENSEC
4 min read
What if thousands of cameras, routers, and DVRs in people's homes suddenly became an army controlled by hackers?
In 2016, that wasn't a hypothetical scenario.
It happened.
A piece of malware called Mirai turned ordinary internet-connected devices into a massive botnet and used them to launch some of the largest DDoS attacks the internet had seen at the time. At its peak, researchers estimated that Mirai had infected more than 600,000 IoT devices.
And the strangest part?
Many of those devices weren't high-powered computers.
They were cameras, routers, and DVRs.
π‘ The Rise of the Smart Device
By 2016, millions of everyday devices were connected to the internet.
Security cameras.
Home routers.
Digital video recorders.
Other small embedded devices.
They were convenient, but many had weak security.
Mirai took advantage of that.
Its original version searched the internet for vulnerable IoT devices and attempted to access them using a list of commonly used default username-and-password combinations.
Once compromised, a device became part of the botnet.
And the larger the botnet became, the more powerful it was.
π¦ From One Device to Hundreds of Thousands
Mirai behaved like a self-propagating worm.
It continuously searched for more potential victims.
One infected device could help expand the botnet.
Then another.
Then another.
Researchers found that Mirai's early growth was extremely fast. Cloudflare's retrospective analysis reported that it reached more than 65,000 infected devices during its first day and eventually exceeded 600,000 infections at its peak.
A collection of ordinary household devices had become a massive distributed network.
π₯ Then the Attacks Started
Mirai wasn't built simply to collect information.
Its infected devices could be commanded to participate in distributed denial-of-service (DDoS) attacks.
Thousands of compromised devices could simultaneously send enormous amounts of traffic toward a target.
The result?
The target struggled to handle the flood of requests.
And legitimate users could no longer access the service.
π° Krebs on Security Was Hit
One of Mirai's first major demonstrations came in September 2016.
The security news site Krebs on Security, run by journalist Brian Krebs, was hit by an enormous DDoS attack.
Cloudflare reported that the attack peaked at approximately 623 Gbps.
The attack was so powerful that it became one of the most notable DDoS incidents of the time.
But this was only the beginning.
β‘ Then Came OVH
Shortly afterward, Mirai was used against OVH, a major hosting provider.
The attack reportedly reached approximately 1 Tbps, according to OVH's measurements cited in Cloudflare's retrospective analysis.
The numbers were extraordinary.
And the machines generating the traffic?
Not supercomputers.
Not powerful servers.
Thousands of relatively small IoT devices.
That changed how security researchers thought about botnets.
π The Attack That Hit Major Websites
Then came October 21, 2016.
A Mirai variant targeted Dyn, a major DNS provider.
DNS is one of the fundamental systems that helps users reach websites.
When Dyn's infrastructure was disrupted, many popular online services became difficult or impossible to access for users in affected regions.
Cloudflare's analysis notes that services including Amazon, GitHub, HBO, Netflix, PayPal, Reddit, and Twitter were among those affected.
The internet itself wasn't literally taken down.
But for millions of people, it certainly felt that way.
π€― The Devices Were Almost Invisible
That's what made Mirai so interesting.
The attackers didn't need to compromise millions of powerful computers.
They assembled a huge army from devices that most people barely thought about.
A security camera sitting in someone's house.
A router sitting under a desk.
A DVR connected to a television system.
Individually, these devices didn't look dangerous.
Together?
They could generate enormous amounts of traffic.
π Then the Source Code Was Released
The story took another unexpected turn.
In September 2016, the alleged author of Mirai released its source code on a hacking forum.
That meant other attackers could study the code and create their own variants.
And that's exactly what happened.
Mirai stopped being just one botnet.
Its code became the foundation for numerous new variants operated by different groups.
One piece of malware had effectively become a blueprint.
π΅οΈ Who Was Behind Mirai?
The investigation eventually led U.S. authorities to three young men: Paras Jha, Josiah White, and Dalton Norman.
In December 2017, the U.S. Department of Justice announced that all three had pleaded guilty to charges related to operating the Mirai botnet.
According to the DOJ, the botnet had reached hundreds of thousands of IoT devices and had been used to conduct powerful DDoS attacks.
The case demonstrated that the massive attacks of 2016 weren't simply the work of an anonymous piece of malware.
Investigators eventually connected the infrastructure and activity to real people.
π‘ Mirai Didn't End in 2016
The original Mirai operation ended, but the malware's story didn't.
After the source code was released, other criminals created their own variants.
Researchers documented numerous independent Mirai-related campaigns targeting different devices and organizations.
In other words:
**The malware was released once.
But its impact continued.**
π The Problem Wasn't Just the Malware
Mirai exposed a much bigger problem with the growing IoT ecosystem.
Many connected devices were deployed with weak security practices.
Some users never changed default credentials.
Some devices were difficult to update.
And many consumers didn't even realize that their everyday devices were potential targets.
Mirai demonstrated what could happen when millions of connected devices are placed online without strong security controls.
π The Legacy of Mirai
Before Mirai, people often thought about botnets as collections of infected computers.
Mirai expanded that idea.
A botnet could now include thousands β or hundreds of thousands β of tiny connected devices.
The lesson wasn't that smart devices were inherently dangerous.
It was that anything connected to the internet can become part of a larger attack if it isn't properly secured.
And in 2016, the world got a very loud demonstration of that fact.
A camera.
A router.
A DVR.
Thousands of them.
And suddenly, the internet had a problem.
Fallow for more guysβ¦β¦.