What Was Mirai? The Botnet That Was Just a List of Passwords

There was no vulnerability. There was a list.

Mirai did not exploit anything. It connected to telnet, tried credentials the manufacturer had printed in the manual, and logged in. That is the entire access mechanism behind one of the largest denial-of-service events in the history of the internet.

What was Mirai?

Mirai was a worm that built a botnet out of consumer internet-connected devices — IP security cameras, digital video recorders, home routers — and rented the resulting firepower out.

It scanned the internet for telnet on ports 23 and 2323. When something answered, it tried a small built-in table of factory username and password pairs. root:xc3511. root:vizxv. admin:admin. If one worked, the device joined the botnet and immediately began scanning for others.

The source code was published on the Hackforums board by a user calling themselves Anna-senpai on 30 September 2016 — a standard move to muddy attribution by ensuring everyone has a copy. It worked, and it also meant Mirai never really ended.

How many passwords, honestly

The shirt says sixty-one. It is worth saying why that number is soft.

The credential table lives in scanner.c in the leaked source, and published counts of it vary between 61 and 62 depending on how you treat repeated entries and weighting. Nobody is wrong; the table is just short enough that people count it by hand and long enough that they disagree.

The precise figure is not the point. The point is that it is a two-digit number. The devices were not brute-forced. Somebody read the manuals.

What answered

Cameras, overwhelmingly. A very large share of the early botnet traced to components made by Hangzhou XiongMai Technology, which supplied boards and firmware to a long list of brands that put their own badge on the outside. xc3511 was a XiongMai default. The company eventually issued a recall.

These devices shared a profile that made them close to ideal:

  • Always on, always connected, on decent domestic bandwidth.
  • No update mechanism, and no expectation of one.
  • A default credential that in many cases could not be changed, because it was baked into the firmware rather than the web interface.
  • An owner who did not think of the object as a computer, and would not have known where to look.

What it did

On 20 September 2016 it hit the security journalist Brian Krebs's site at roughly 620 Gbps — at the time among the largest attacks ever recorded, and large enough that Akamai, which had been hosting him pro bono, could not justify continuing to absorb it. The site went dark until Google's Project Shield took it on.

Days later it hit the French host OVH at around a terabit per second, with peaks reported above that.

Then on 21 October 2016 it went after Dyn, a managed DNS provider. Dyn was not the target in any meaningful sense — it was the phone book. Taking it down took Twitter, Reddit, Netflix, Spotify, GitHub, Airbnb and PayPal off the map for much of the United States for most of a day, without a single packet being sent at any of them.

Dyn's own post-incident analysis put the attack at roughly 100,000 malicious endpoints. Early reporting of “tens of millions of IP addresses” reflected the address count Dyn observed, inflated by DNS retry behaviour, not the size of the botnet.

Correcting the record, twice

The people who took down Dyn were probably not the people who wrote Mirai. The source had been public for three weeks by 21 October. The authors — Paras Jha, Josiah White and Dalton Norman, all in their early twenties — pleaded guilty in December 2017 to charges relating to Mirai, and the Dyn attack has never been attributed to them. Almost every retelling runs the two together.

Mirai was trivial to remove. It lived only in memory. Unplugging a device and plugging it back in cleaned it completely. That sounds like a saving grace and is the opposite: reinfection took minutes, because a reboot restores the default password too. There was nothing to disinfect. The vulnerable state was the factory state.

Why they built it

Not espionage, and not politics. Minecraft.

Hosting Minecraft servers was a real business with real money in it, and servers that go down lose players. Jha ran a DDoS mitigation company called ProTraf Solutions. The court record and the FBI's own account describe a motive combining DDoS-for-hire revenue with pressure on rival hosting providers — the protection racket structure, applied to a game.

All three cooperated extensively with the FBI afterwards. The sentences, handed down in September 2018, were probation, substantial community service, and restitution.

What is still true

Because the source is public, Mirai never stopped — it forked. Satori, Okiru, Masuta, Mukashi and a long tail of others are all Mirai derivatives, most of them adding actual exploits to the credential list rather than replacing it.

The regulatory response took years and went after the root cause rather than the malware: California's SB-327 and the UK's Product Security and Telecommunications Infrastructure Act both ban universal default passwords on consumer connected devices. Both arrived long after the devices in question had shipped.

The durable lesson is about ownership. Every device in that botnet had a buyer, and not one of them had an operator.

Further reading

  • Antonakakis et al. — Understanding the Mirai Botnet (USENIX Security, 2017). The measurement paper; the definitive account of size and composition.
  • Brian Krebs — Who is Anna-Senpai, the Mirai Worm Author? (2017), and his write-ups of the attack on his own site.
  • Dyn — Dyn Analysis Summary of Friday October 21 Attack.
  • US Department of Justice — the Mirai plea and sentencing documents, District of Alaska.

EXHIBIT 0010 — MIRAI

We put it on a shirt. A wall of cameras, all of them pointed at you, wired together and braiding down into one cable that leaves the frame considerably thicker than it arrived.

Most people will read it as a drawing of surveillance. A smaller number will read the three lines in the corner and recognise them as factory defaults.

That's the whole idea.

View the Mirai shirt — EXHIBIT 0010

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.