/LikelyMalware

Mirai: Back to The Future

Timewarp #2. Ten years of the malware that only ever asked nicely.

September 30, 2026 11 min read

Timewarp #2. Ten years of the malware that only ever asked nicely.

Hello there cyber fanatics! Ten years ago a piece of malware went around the internet asking devices for their password, and enough of them said yes to knock some of the largest sites in the world offline. That is the entire technique. There is no exploit chain to draw on a whiteboard. There is no memory corruption trick to explain. Mirai asked, and hundreds of thousands of cameras, DVRs and home routers answered. Mirai is my favourite malware family to talk about, because it is the cleanest proof I own that the circle doesn't break. It was assembled out of older malware, it leaked, and then it turned into a franchise that is still running in 2026. The kid who wrote it left behind a legacy I am fairly sure he never wanted. So this one is about the malware. Let's go.

Recycled From What?

The first public analysis of Mirai came from the volunteer crew at MalwareMustDie, in a blog post at the end of August 2016, and the title tells you everything: Linux/Mirai, how an old ELF malcode is recycled. Their read at the time was that Mirai was the next generation of GayFgt, LizKebab and Torlus, which most of us know as BASHLITE. They found chunks of code that were basically the same. Sit with that for a second. The most famous IoT botnet in history, the one that gets a slide in every board deck about connected devices, opens its own origin story as somebody's fork of a two-year-old Linux DDoS tool. The name is Japanese for "the future," taken from the anime Mirai Nikki. The author was an anime kid who called himself Anna-senpai. That is the level we are operating on here, and I mean that as a compliment, because the thing worked better than most funded products.

The Whole Exploit Chain Was a Password List

Here is the technical core of Mirai, and I am not simplifying it for the blog. This really is it. The bot picks random IPv4 addresses and fires SYN probes at Telnet, port 23, or port 2323 when it feels like it. When something answers, it works through a hardcoded table of username and password pairs. In the leaked source that table is 62 lines long, with one duplicate, so 61 unique combinations. Sixty-one. That is the full offensive capability. root/xc3511, admin/admin, root/vizxv, support/support, and a list of others that came straight off the spec sheets of cheap OEM firmware.

Mirai hardcoded credential pairs from scanner.c

Hardcoded username/password pairs from Mirai's scanner table, as published in Fortinet's Mirai code-reuse analysis. Source: Fortinet.

Mirai credential table from published source analysis

Mirai credential / related source table from Radware's Mirai source-code write-up. Source: Radware.

A successful login gets reported to a separate loader, the loader drops the architecture-appropriate binary, and the device joins the botnet. USENIX researchers later put the peak at over 600,000 devices, with more than 65,000 compromised on the first day. Read the vendor position out loud and it falls over by itself. The device is secure, it has a password, the password is admin, and the username is also admin, and it is printed in the manual, and the manual is a PDF on a support site, and the customer can change it any time they like, and remote management is on by default because that is convenient, and the firmware has not been updated since the factory because the company that made it no longer exists, and it is really not our problem. Nobody in that chain was paid to break the default. Mirai just showed up and collected. This is the malware I use when somebody junior asks me what they should be scared of. The boring stuff, at scale, beats the clever stuff almost every time.

Polite Enough to Skip the Pentagon

The parts of Mirai that I actually enjoy are the housekeeping. It was hardwired to skip IP ranges belonging to General Electric, Hewlett-Packard and the US Department of Defense, along with a few other blocks. Somebody sat down and wrote an avoid-list. It is the closest thing to a risk assessment in the whole codebase. Once inside a device, Mirai killed competing malware it found running there, which is the most honest thing in the source. There was a land grab happening over the same finite pool of weak devices, and Mirai wanted the camera to itself. And it lived only in memory. A reboot cleaned the device completely. The catch is that the device came back up with the same password it had before, so reinfection took minutes. The fix was always to change the credentials and then reboot, in that order, which is roughly the same advice we were giving in 2016 and are still giving in 2026.

Everything After Was a Consequence

I am going to move fast here, because the incidents are the part everybody already knows. On 20 September 2016, Mirai hit Brian Krebs's site with roughly 620 Gbps as measured by Akamai, and kept it offline for nearly four days. Around the same window it hit the French hoster OVH at close to a terabit. On 21 October 2016, a Mirai botnet flooded Dyn's managed DNS and Twitter, Netflix, Reddit, Spotify and PayPal went dark on and off across Europe and North America. Those are the headlines. They are downstream of the password list.

The Sequels

On Friday 30 September 2016, Anna-senpai posted the Mirai source on Hackforums. The stated reason was classic underground theatre: too many eyes on IoT now, time to leave, here is the code. Krebs wrote the leak up on 1 October 2016.

Hackforums post: Anna-senpai releases Mirai source

The Hackforums post where Anna-senpai dropped the Mirai source, as published by Krebs on Security (1 Oct 2016). Source: Krebs on Security.

That single upload is the reason we are still talking about this. Paras Jha, Josiah White and Dalton Norman pleaded guilty in December 2017 to building and running the original. Prosecutors said at the time that they did not think those three were the ones who hit Dyn, because the code had already leaked and forked. Writing the malware and running every later wave of it stopped being the same job the moment that zip went up.

Hajime Means Beginning

Paras Jha was a college kid who liked anime and wanted to sell DDoS protection to Minecraft servers. What he walked away from was a naming convention and an entire genre, and I do not believe for a second that he saw it coming. Days after the source went public, Sam Edwards and Ioannis Profetis at Rapidity Networks found something else crawling through the same cameras. They called it Hajime, which is Japanese for "beginning." Let me be careful here, because this one gets repeated wrong a lot, and I almost repeated it myself. Hajime was written separately from Mirai. It talked to its operator over a peer-to-peer network instead of a hardcoded C2, and it carried no DDoS module at all. Once it owned a device it closed the ports Mirai came in through and left a signed note behind: "Just a white hat, securing some systems." By April 2017 it was sitting on around 300,000 devices.

Hajime white-hat note left on infected devices

Hajime's signed note: "Just a white hat, securing some systems." Source: Radware / Rapidity Networks discovery write-ups.

So the first thing to arrive after Mirai was a rival that turned up to take the same cameras away from it, and the name it got was "beginning." The name turned out to describe the decade. Everything since has been variations on the same skeleton, and the researchers naming them kept the joke running. Satori in December 2017, which took over 280,000 devices in twelve hours. Then Okiru, found by MalwareMustDie in January 2018, the first malware anybody had seen compiled for ARC processors, carrying 114 credentials instead of 61. Okiru means "to wake up." After that Masuta, Reaper, Mukashi on Zyxel NAS boxes in 2020, Moobot, Gayfemboy. Academic work counts them in the dozens. The children also learned something. The original needed you to leave the password alone. The descendants stopped waiting for that and started carrying CVEs. Two of them were written up this April. Akamai tracked one called Tuxnokill going after D-Link DIR-823X routers with CVE-2025-29635, TP-Link Archer AX21 with CVE-2023-1389, and ZTE ZXV10 gateways. FortiGuard tracked another called Nexcorium, run by a crew calling itself Nexus Team, hitting TBK DVRs with CVE-2024-3721 and bundling a Huawei bug from 2017 for good measure. A Huawei vulnerability from 2017, exploited in 2026, by a descendant of a 2016 botnet, which was itself a fork of a 2014 one. This industry does not throw anything away.

Still Lurking

If you want to see how far the family travelled, look at who is still getting hit. In September 2016 Mirai held Brian Krebs's site down for nearly four days at around 620 Gbps. In May 2025 he got hit again, by a botnet called Aisuru, also known as Airashi. 6.3 Tbps, about 585 million packets per second, and it was finished in 45 seconds. Researchers file Aisuru as TurboMirai-class, and Krebs is careful to point out it is no straight clone. What it keeps from the original is the direct-path UDP, TCP, GRE and DNS flooding, and it adds carpet-bombing and application-layer work on top. By October 2025 it was being blamed for attacks north of 20 Tbps against US ISPs. And what is it built from? Consumer broadband routers, CCTV cameras and DVRs, running the same kind of OEM firmware that Mirai was logging into with admin/admin.

The Circle Doesn't Break

Censys published a piece in August this year on a decade of structural neglect in IoT, and the number that stuck with me is 117,000 GPON home gateway login pages sitting on the internet with default credentials. Cloudflare had Mirai-based traffic as the third most common network-layer DDoS attack type in the first quarter of 2025. The malware is ten years old. The technique is older than the malware. It still works. And I build agentic AI systems every day, so I want to say the uncomfortable part out loud. I keep finding the same shape in that stack. Servers and tools that ship open because that is what makes the demo work. Credentials in environment variables that everyone agrees are temporary. Management interfaces exposed because somebody needed to check one thing once. Mirai got its army from an industry shipping convenience and calling it a product. We moved that habit up the stack and changed nothing else about it. My prediction: the next botnet that embarrasses all of us gets its foothold from a default that somebody shipped on purpose, in something we started deploying in the last two years, and the write-up will open by calling it novel. Unfortunately. So go and count your defaults, starting with the things nobody put in the asset inventory. The camera in the lobby, the sensor in the server room, the box a contractor installed in 2021 and never mentioned again. I hope I was able to improve 0.1% of your knowledge. Have fun, and good luck!


Sources