Mirai was the 2016 malware that infected internet-connected devices and helped launch one of the largest DDoS attacks.
Mirai scanned the internet for devices such as routers, cameras, and digital video recorders that still used factory-set or easily guessed usernames and passwords. It enlisted vulnerable devices into a botnet and used them to overwhelm targets with distributed denial-of-service traffic.
In October 2016, Mirai’s operators attacked Dyn, a company that provided internet infrastructure and DNS services. The disruption made many well-known websites difficult or impossible to reach for users in parts of North America and Europe. Mirai’s source code was later released publicly, allowing other criminals to create variants.
The malware highlighted a basic but persistent security problem: internet-connected equipment often ships with default credentials and receives limited maintenance. Mirai did not need sophisticated exploitation for many devices; weak authentication was enough to turn them into attack infrastructure.