Source material for Lurk More Ch. 7 (Hackers and Trolls) — the Mirai botnet, the Dyn attack, BrickerBot's Internet Chemotherapy campaign, and the vigilante botnets that filled the institutional vacuum.

Research compiled for Lurk More Ch. 7 — “Hackers and Trolls,” section “Internet Chemotherapy: When Nobody’s Job Becomes Somebody’s.”


The Mirai Botnet

Authors

  • Paras Jha (aka “Anna-senpai”) — Rutgers University student (Krebs on Security)
  • Josiah White — co-author (DOJ)
  • Dalton Norman — co-author (DOJ)

Origin

Built to DDoS competing Minecraft server hosting services and sell DDoS protection. The botnet spread by scanning for IoT devices (security cameras, DVRs, home routers) and logging in with a table of 62 factory default credentials (admin/admin, root/root, etc.).

Jha open-sourced the Mirai code in September 2016 to diffuse attribution. (Krebs on Security)

The Dyn Attack — October 21, 2016

  • Target: Dyn, a major DNS provider
  • Method: Three waves of Mirai-powered DDoS
  • Impact: Twitter, Netflix, Reddit, New York Times, Spotify, GitHub, and others offline for hours across the US East Coast
  • Scale: Approximately 100,000 compromised consumer IoT devices
  • No criminal charges for the Dyn attack specifically; the three authors were charged for creating and operating Mirai (DOJ)

Sentencing — December 2017 / September 2018

  • All three pled guilty December 2017 (DOJ) (Krebs on Security)
  • Sentenced to five years’ probation, 2,500 hours of community service, $127,000 restitution (Krebs on Security)
  • Reduced for what the FBI called “extraordinary cooperation” in identifying other cybercriminals (Krebs on Security)
  • No manufacturers were charged for shipping devices with default/hardcoded credentials

The Acquisition

  • Oracle acquired Dyn in November 2016 — approximately one month after the attack
  • Estimated price: ~$600 million
  • Source

BrickerBot / “Internet Chemotherapy”

The Author: janit0r

  • Anonymous actor using the handle “janit0r” on Hack Forums (Bleeping Computer)
  • Self-described as “The Janitor” — cleaning up the internet’s mess
  • Never identified, never caught
  • Handle went silent December 2017 and has not resurfaced (Bleeping Computer)

What BrickerBot Did

  • Started November 2016, weeks after the Dyn attack (Bleeping Computer)
  • Logged into vulnerable IoT devices using the same default credentials Mirai exploited
  • Instead of conscripting devices into a botnet, permanently destroyed them by overwriting flash storage with random data, corrupting firmware
  • A bricked device cannot be recruited for the next Dyn

Timeline

  • November 2016: janit0r begins Internet Chemotherapy
  • April 2017: Radware first publicly identifies and names BrickerBot (BrickerBot.1 and BrickerBot.2 variants) (Radware)
  • April 2017: janit0r gives interview to Catalin Cimpanu at Bleeping Computer, claims 2 million devices bricked (Bleeping Computer)
  • December 10, 2017: janit0r announces retirement, claims over 10 million devices bricked (Bleeping Computer)
  • The number is unverifiable, but the population of Mirai-vulnerable devices declined measurably during BrickerBot’s active period

Stated Motivation

“People are already tired of waiting for someone to address the IoT ecosystem problem.” Manufacturers would not patch. ISPs would not quarantine. No regulation required secure defaults. The vigilante response: destroy the broken devices before they could be weaponized.


Other Vigilante Botnets

Linux.Wifatch (discovered 2015)

  • Discovered by Symantec
  • Infected routers, closed Telnet ports, left messages urging owners to update firmware
  • No malicious payload
  • Attributed to a group calling themselves “The White Team”
  • Source

Hajime (discovered October 2016)

  • Appeared the same month as Mirai
  • Peer-to-peer botnet that competed with Mirai for the same vulnerable devices
  • Blocked common exploit ports
  • Displayed message: “Just a white hat, securing some systems.”
  • No DDoS capability
  • Author never identified
  • Source

The Structural Argument

No one was responsible for IoT security:

  • Manufacturers shipped devices with default or hardcoded passwords. No regulation required otherwise.
  • ISPs passed the traffic without inspection.
  • The FTC had no enforceable standard.
  • After the largest DDoS attack in history: the three college kids got probation, the manufacturers faced nothing, and the anonymous vigilante who materially reduced the attack surface was a fugitive.

The institutional vacuum was filled by unauthorized actors — janit0r, The White Team, the Hajime author — who committed crimes to fix a problem that nobody with authority was willing to fix.


Key Sources

Krebs on Security

DOJ

BrickerBot Coverage

Vigilante Botnets

Author’s Prior Work

Additional Context