What is the Mirai Botnet?
Mirai is a pervasive Internet-of-Things (IoT) botnet that first surfaced in 2016 and rapidly evolved into a foundational DDoS framework. By scanning for devices with default or weak credentials and installing a lightweight in-memory agent, Mirai and its descendants have mounted some of the largest and most disruptive volumetric and application-layer DDoS campaigns in recent history.
Editor’s note: This article has been updated to cover recent market trends as of 2026.
Mirai is malware that compromises internet-connected devices—especially IP cameras, DVRs, home routers, and other poorly secured IoT endpoints—by logging in using default or hard-coded credentials and installing a lightweight agent in memory. Infected devices join a distributed botnet controlled by command-and-control (C2) infrastructure and can be instructed to launch volumetric and application-layer attacks on chosen targets. The danger of Mirai stems from the combination of always-on devices, widespread insecure defaults, and the low cost for attackers to operate large botnets.
Mirai was publicly observed in 2016 and quickly drew attention after a series of high-profile incidents, notably attacks against KrebsOnSecurity and the managed-DNS provider Dyn in October 2016 that disrupted access to major internet platforms. Following the public release of Mirai’s source code, dozens of variants and derivative families appeared (for example, Satori, Gafgyt, Masuta and others), accelerating the proliferation of IoT botnets. Law enforcement actions in subsequent years identified and charged some original authors, but the public code and the ease of reuse ensured Mirai’s continued relevance.
Mirai typically spreads via automated scanning: scanners probe IP ranges for reachable management services (Telnet, SSH, TR-069 endpoints) and attempt logins using hard-coded lists of common default username/password pairs. When a device authenticates, Mirai loads an in-memory payload that avoids persistent storage; often a reboot clears the infection. Infected bots periodically contact C2 servers for commands and can be instructed to execute coordinated attack campaigns, including UDP/TCP floods, DNS amplification, HTTP floods, and protocol-specific floods targeting gaming and VOIP services.
The typical kill-chain is straightforward: reconnaissance and scanning, brute-force credential attempts or exploit delivery, payload installation, lateral scanning and propagation, and finally attack execution. Mirai variants often add exploit modules to expand the pool of vulnerable devices, and C2 infrastructures have evolved to include redundant servers, fast-flux DNS, and peer-assisted models for resiliency.
Mirai as an Evolving IoT Botnet Ecosystem
As of 2026, Mirai is a reusable malware lineage and attack framework that continues to shape IoT-driven DDoS activity. Radware describes Mirai as one of the defining IoT botnets because its leaked source code enabled attackers to create customized variants and rapidly expand DDoS capabilities across poorly secured connected devices.
The key risk is that Mirai’s original model still works: scan the internet for exposed devices, compromise them through weak credentials or known vulnerabilities, and use them as disposable attack nodes. Because routers, DVRs, IP cameras, gateways, and other embedded devices often remain online for long periods, attackers can assemble large pools of always-available infrastructure for volumetric and application-layer attacks.
Shift Toward Vulnerability-Driven Exploitation
Modern Mirai activity has moved beyond basic default-password attacks. While credential abuse remains relevant, recent campaigns increasingly rely on public exploits and known CVEs to compromise routers, DVRs, and other edge devices at scale.
In April 2026, public reporting described a Mirai campaign exploiting CVE-2025-29635 in end-of-life D-Link DIR-823X routers, with attackers using the flaw to deploy a Mirai variant known as “tuxnokill.” Around the same period, FortiGuard Labs analyzed “Nexcorium,” a multi-architecture Mirai variant delivered through CVE-2024-3721 against TBK DVR devices.
These campaigns show that Mirai operators increasingly depend on exposed, outdated, and unsupported devices. Once a proof-of-concept exploit becomes public, attackers can integrate it into automated botnet workflows and quickly expand the population of vulnerable targets.
Expansion of Attack Techniques
Mirai-family botnets still rely on classic DDoS methods such as UDP floods, TCP floods, DNS floods, GRE floods, HTTP floods, and protocol-specific attack traffic. Radware’s early Mirai research noted that Mirai helped change DDoS defense assumptions by demonstrating how large numbers of compromised IoT devices could generate massive attacks and combine multiple attack vectors.
In the 2025-2026 threat landscape, this matters because DDoS attacks are becoming faster, larger, and more automated. Radware’s 2026 Global Threat Analysis Report highlights a “time compression” problem, where many record-level DDoS attacks last less than 60 seconds, making manual response and human-in-the-loop mitigation increasingly ineffective.
Current Threat Landscape in 2026
The Mirai threat landscape is fragmented and highly reusable. Some operators still rely on leaked code and simple scanning, while more capable actors add exploit modules, multi-architecture payloads, obfuscated configurations, persistence features, and more resilient command-and-control infrastructure.
Radware’s 2025 and 2026 threat reporting points to a broader DDoS environment defined by higher frequency, larger volumes, longer durations, and more complex attack surfaces. In that context, Mirai-family botnets remain important because they provide attackers with a low-cost way to turn vulnerable IoT and edge devices into scalable attack infrastructure.
Defending against Mirai-style IoT botnets requires an integrated approach: device-level hygiene, network-edge behavioral detection, cloud-based scrubbing, application-layer protections, and practiced operational playbooks.
1. Device hardening and secure provisioning
Ensure device manufacturers implement secure defaults (unique default passwords, disabled Telnet where not required, signed firmware, secure update mechanisms) while operators enforce strong credentials, network segmentation for IoT subnets, and automated update workflows.
How Radware Helps: Radware Emergency Response Team’s Threat Alerts and analysis of IoT/botnet trends.
2. Network-edge detection and automated mitigation
Deploy inline network-edge protections to detect volumetric and protocol-layer anomalies early. Use behavioral baselining and automated mitigation to block malicious flows before they exhaust ISP links, and integrate upstream scrubbing for overflow scenarios.
How Radware Helps: DefensePro provides wire-speed, protocol-aware protection at the network edge while Cloud DDoS Protection Service offers hyperscale scrubbing for overflow traffic.
3. Application-layer protections & WAF
Protect web-facing services and application endpoints with WAFs, behavioral L7 DDoS detection, challenge-response flows, and API protections. For gaming and other service-specific protocols, enforce rate limits and connection hardening.
How Radware Helps: Cloud WAF Service and Web DDoS Protection provide adaptive L7 defenses and real-time signature generation.
4. Threat intelligence, bot management & telemetry
Centralize telemetry from network and cloud defenses and feed it into threat-intelligence services that update signatures and blocklists. Use bot management tools to distinguish legitimate client behavior from automated IoT traffic and reduce false positives.
How Radware Helps: Threat Intelligence Subscriptions and Bot Manager deliver curated intelligence and bot classification to support automated mitigation.
5. Operations & readiness
Prepare runbooks, pre-authorize diversion with ISPs, and practice tabletop exercises that cover mirrored IoT-botnet scenarios. Rapid coordination between NOC, security teams, and vendors minimizes time-to-mitigation.
Mirai-powered attacks in 2016—most notably the Dyn managed-DNS outage—demonstrated how insecure IoT devices could be weaponized to disrupt major internet services. Later Mirai-derived campaigns targeted gaming services and ISPs, showing the breadth of targets and the need for systemic IoT security improvements.
Mirai’s legacy is a reminder that inexpensive, always-on devices with weak defaults create systemic risk. Key takeaways: prioritize secure defaults and patch management, enforce network segmentation for IoT, adopt layered DDoS defenses combining edge detection and cloud scrubbing, and maintain operational readiness through runbooks and ERT coordination. Organizations that combine these controls will significantly reduce their exposure to IoT botnet-driven disruption.