Mirai, BrickerBot, and IoT Vigilantism
Research compiled for Lurk More Ch. 7 — “Hackers and Trolls,” section “Internet Chemotherapy: When Nobody’s Job Becomes Somebody’s.”
The Mirai Botnet
Authors
- Paras Jha (aka “Anna-senpai”) — Rutgers University student (Krebs on Security)
- Josiah White — co-author (DOJ)
- Dalton Norman — co-author (DOJ)
Origin
Built to DDoS competing Minecraft server hosting services and sell DDoS protection. The botnet spread by scanning for IoT devices (security cameras, DVRs, home routers) and logging in with a table of 62 factory default credentials (admin/admin, root/root, etc.).
Jha open-sourced the Mirai code in September 2016 to diffuse attribution. (Krebs on Security)
The Dyn Attack — October 21, 2016
- Target: Dyn, a major DNS provider
- Method: Three waves of Mirai-powered DDoS
- Impact: Twitter, Netflix, Reddit, New York Times, Spotify, GitHub, and others offline for hours across the US East Coast
- Scale: Approximately 100,000 compromised consumer IoT devices
- No criminal charges for the Dyn attack specifically; the three authors were charged for creating and operating Mirai (DOJ)
Sentencing — December 2017 / September 2018
- All three pled guilty December 2017 (DOJ) (Krebs on Security)
- Sentenced to five years’ probation, 2,500 hours of community service, $127,000 restitution (Krebs on Security)
- Reduced for what the FBI called “extraordinary cooperation” in identifying other cybercriminals (Krebs on Security)
- No manufacturers were charged for shipping devices with default/hardcoded credentials
The Acquisition
- Oracle acquired Dyn in November 2016 — approximately one month after the attack
- Estimated price: ~$600 million
- Source
BrickerBot / “Internet Chemotherapy”
The Author: janit0r
- Anonymous actor using the handle “janit0r” on Hack Forums (Bleeping Computer)
- Self-described as “The Janitor” — cleaning up the internet’s mess
- Never identified, never caught
- Handle went silent December 2017 and has not resurfaced (Bleeping Computer)
What BrickerBot Did
- Started November 2016, weeks after the Dyn attack (Bleeping Computer)
- Logged into vulnerable IoT devices using the same default credentials Mirai exploited
- Instead of conscripting devices into a botnet, permanently destroyed them by overwriting flash storage with random data, corrupting firmware
- A bricked device cannot be recruited for the next Dyn
Timeline
- November 2016: janit0r begins Internet Chemotherapy
- April 2017: Radware first publicly identifies and names BrickerBot (BrickerBot.1 and BrickerBot.2 variants) (Radware)
- April 2017: janit0r gives interview to Catalin Cimpanu at Bleeping Computer, claims 2 million devices bricked (Bleeping Computer)
- December 10, 2017: janit0r announces retirement, claims over 10 million devices bricked (Bleeping Computer)
- The number is unverifiable, but the population of Mirai-vulnerable devices declined measurably during BrickerBot’s active period
Stated Motivation
“People are already tired of waiting for someone to address the IoT ecosystem problem.” Manufacturers would not patch. ISPs would not quarantine. No regulation required secure defaults. The vigilante response: destroy the broken devices before they could be weaponized.
Other Vigilante Botnets
Linux.Wifatch (discovered 2015)
- Discovered by Symantec
- Infected routers, closed Telnet ports, left messages urging owners to update firmware
- No malicious payload
- Attributed to a group calling themselves “The White Team”
- Source
Hajime (discovered October 2016)
- Appeared the same month as Mirai
- Peer-to-peer botnet that competed with Mirai for the same vulnerable devices
- Blocked common exploit ports
- Displayed message: “Just a white hat, securing some systems.”
- No DDoS capability
- Author never identified
- Source
The Structural Argument
No one was responsible for IoT security:
- Manufacturers shipped devices with default or hardcoded passwords. No regulation required otherwise.
- ISPs passed the traffic without inspection.
- The FTC had no enforceable standard.
- After the largest DDoS attack in history: the three college kids got probation, the manufacturers faced nothing, and the anonymous vigilante who materially reduced the attack surface was a fugitive.
The institutional vacuum was filled by unauthorized actors — janit0r, The White Team, the Hajime author — who committed crimes to fix a problem that nobody with authority was willing to fix.
Key Sources
Krebs on Security
- “Who Is Anna-Senpai, the Mirai Worm Author?” January 18, 2017
- “Mirai IoT Botnet Co-Authors Plead Guilty.” December 13, 2017
- “Mirai Botnet Authors Avoid Jail Time.” September 19, 2018
DOJ
BrickerBot Coverage
- Cimpanu, Catalin. “BrickerBot Author Claims He Bricked Two Million Devices.” Bleeping Computer, April 24, 2017
- Cimpanu, Catalin. “BrickerBot Author Retires Claiming to Have Bricked over 10 Million IoT Devices.” Bleeping Computer, December 11, 2017
- Radware. “BrickerBot PDoS Attack: Back with a Vengeance.” April 2017
Vigilante Botnets
- Symantec. “Is There an Internet of Things Vigilante Out There?” October 1, 2015
- Symantec. “Hajime Worm Battles Mirai for Control of the Internet of Things.” April 18, 2017
Author’s Prior Work
Additional Context
Prefer RSS? Subscribe here.