What Is the Mirai Botnet?


Mirai Botnet Article Image

What is the Mirai Botnet?

Mirai is a pervasive Internet-of-Things (IoT) botnet that first surfaced in 2016 and rapidly evolved into a foundational DDoS framework. By scanning for devices with default or weak credentials and installing a lightweight in-memory agent, Mirai and its descendants have mounted some of the largest and most disruptive volumetric and application-layer DDoS campaigns in recent history.

Editor’s note: This article has been updated to cover recent market trends as of 2026.

Introduction: Defining Mirai

Mirai is malware that compromises internet-connected devices—especially IP cameras, DVRs, home routers, and other poorly secured IoT endpoints—by logging in using default or hard-coded credentials and installing a lightweight agent in memory. Infected devices join a distributed botnet controlled by command-and-control (C2) infrastructure and can be instructed to launch volumetric and application-layer attacks on chosen targets. The danger of Mirai stems from the combination of always-on devices, widespread insecure defaults, and the low cost for attackers to operate large botnets.

Historical Background & Key Milestones

Mirai was publicly observed in 2016 and quickly drew attention after a series of high-profile incidents, notably attacks against KrebsOnSecurity and the managed-DNS provider Dyn in October 2016 that disrupted access to major internet platforms. Following the public release of Mirai’s source code, dozens of variants and derivative families appeared (for example, Satori, Gafgyt, Masuta and others), accelerating the proliferation of IoT botnets. Law enforcement actions in subsequent years identified and charged some original authors, but the public code and the ease of reuse ensured Mirai’s continued relevance.

How Mirai Works: Infection, Botnet Construction & Attack Lifecycle

Mirai typically spreads via automated scanning: scanners probe IP ranges for reachable management services (Telnet, SSH, TR-069 endpoints) and attempt logins using hard-coded lists of common default username/password pairs. When a device authenticates, Mirai loads an in-memory payload that avoids persistent storage; often a reboot clears the infection. Infected bots periodically contact C2 servers for commands and can be instructed to execute coordinated attack campaigns, including UDP/TCP floods, DNS amplification, HTTP floods, and protocol-specific floods targeting gaming and VOIP services.

The typical kill-chain is straightforward: reconnaissance and scanning, brute-force credential attempts or exploit delivery, payload installation, lateral scanning and propagation, and finally attack execution. Mirai variants often add exploit modules to expand the pool of vulnerable devices, and C2 infrastructures have evolved to include redundant servers, fast-flux DNS, and peer-assisted models for resiliency.

Mirai Attack Variants & Threat Landscape in 2026

Mirai as an Evolving IoT Botnet Ecosystem

As of 2026, Mirai is a reusable malware lineage and attack framework that continues to shape IoT-driven DDoS activity. Radware describes Mirai as one of the defining IoT botnets because its leaked source code enabled attackers to create customized variants and rapidly expand DDoS capabilities across poorly secured connected devices.

The key risk is that Mirai’s original model still works: scan the internet for exposed devices, compromise them through weak credentials or known vulnerabilities, and use them as disposable attack nodes. Because routers, DVRs, IP cameras, gateways, and other embedded devices often remain online for long periods, attackers can assemble large pools of always-available infrastructure for volumetric and application-layer attacks.

Shift Toward Vulnerability-Driven Exploitation

Modern Mirai activity has moved beyond basic default-password attacks. While credential abuse remains relevant, recent campaigns increasingly rely on public exploits and known CVEs to compromise routers, DVRs, and other edge devices at scale.

In April 2026, public reporting described a Mirai campaign exploiting CVE-2025-29635 in end-of-life D-Link DIR-823X routers, with attackers using the flaw to deploy a Mirai variant known as “tuxnokill.” Around the same period, FortiGuard Labs analyzed “Nexcorium,” a multi-architecture Mirai variant delivered through CVE-2024-3721 against TBK DVR devices.

These campaigns show that Mirai operators increasingly depend on exposed, outdated, and unsupported devices. Once a proof-of-concept exploit becomes public, attackers can integrate it into automated botnet workflows and quickly expand the population of vulnerable targets.

Expansion of Attack Techniques

Mirai-family botnets still rely on classic DDoS methods such as UDP floods, TCP floods, DNS floods, GRE floods, HTTP floods, and protocol-specific attack traffic. Radware’s early Mirai research noted that Mirai helped change DDoS defense assumptions by demonstrating how large numbers of compromised IoT devices could generate massive attacks and combine multiple attack vectors.

In the 2025-2026 threat landscape, this matters because DDoS attacks are becoming faster, larger, and more automated. Radware’s 2026 Global Threat Analysis Report highlights a “time compression” problem, where many record-level DDoS attacks last less than 60 seconds, making manual response and human-in-the-loop mitigation increasingly ineffective.

Current Threat Landscape in 2026

The Mirai threat landscape is fragmented and highly reusable. Some operators still rely on leaked code and simple scanning, while more capable actors add exploit modules, multi-architecture payloads, obfuscated configurations, persistence features, and more resilient command-and-control infrastructure.

Radware’s 2025 and 2026 threat reporting points to a broader DDoS environment defined by higher frequency, larger volumes, longer durations, and more complex attack surfaces. In that context, Mirai-family botnets remain important because they provide attackers with a low-cost way to turn vulnerable IoT and edge devices into scalable attack infrastructure.

Mitigations & Defensive Playbook

Defending against Mirai-style IoT botnets requires an integrated approach: device-level hygiene, network-edge behavioral detection, cloud-based scrubbing, application-layer protections, and practiced operational playbooks.

1. Device hardening and secure provisioning

Ensure device manufacturers implement secure defaults (unique default passwords, disabled Telnet where not required, signed firmware, secure update mechanisms) while operators enforce strong credentials, network segmentation for IoT subnets, and automated update workflows.

How Radware Helps: Radware Emergency Response Team’s Threat Alerts and analysis of IoT/botnet trends.

2. Network-edge detection and automated mitigation

Deploy inline network-edge protections to detect volumetric and protocol-layer anomalies early. Use behavioral baselining and automated mitigation to block malicious flows before they exhaust ISP links, and integrate upstream scrubbing for overflow scenarios.

How Radware Helps: DefensePro provides wire-speed, protocol-aware protection at the network edge while Cloud DDoS Protection Service offers hyperscale scrubbing for overflow traffic.

3. Application-layer protections & WAF

Protect web-facing services and application endpoints with WAFs, behavioral L7 DDoS detection, challenge-response flows, and API protections. For gaming and other service-specific protocols, enforce rate limits and connection hardening.

How Radware Helps: Cloud WAF Service and Web DDoS Protection provide adaptive L7 defenses and real-time signature generation.

4. Threat intelligence, bot management & telemetry

Centralize telemetry from network and cloud defenses and feed it into threat-intelligence services that update signatures and blocklists. Use bot management tools to distinguish legitimate client behavior from automated IoT traffic and reduce false positives.

How Radware Helps: Threat Intelligence Subscriptions and Bot Manager deliver curated intelligence and bot classification to support automated mitigation.

5. Operations & readiness

Prepare runbooks, pre-authorize diversion with ISPs, and practice tabletop exercises that cover mirrored IoT-botnet scenarios. Rapid coordination between NOC, security teams, and vendors minimizes time-to-mitigation.

How Radware Helps: Radware’s Emergency Response Team (ERT) provides 24x7 expert support, while cloud analytics accelerate classification and post-incident tuning.

Case Studies & Real-World Examples

Mirai-powered attacks in 2016—most notably the Dyn managed-DNS outage—demonstrated how insecure IoT devices could be weaponized to disrupt major internet services. Later Mirai-derived campaigns targeted gaming services and ISPs, showing the breadth of targets and the need for systemic IoT security improvements.

Future Outlook & Key Takeaways

Mirai’s legacy is a reminder that inexpensive, always-on devices with weak defaults create systemic risk. Key takeaways: prioritize secure defaults and patch management, enforce network segmentation for IoT, adopt layered DDoS defenses combining edge detection and cloud scrubbing, and maintain operational readiness through runbooks and ERT coordination. Organizations that combine these controls will significantly reduce their exposure to IoT botnet-driven disruption.

Contact Radware Sales

Our experts will answer your questions, assess your needs, and help you understand which products are best for your business.

Already a Customer?

We’re ready to help, whether you need support, additional services, or answers to your questions about our products and solutions.

Locations
Get Answers Now from KnowledgeBase
Get Free Online Product Training
Engage with Radware Technical Support
Join the Radware Customer Program

Get Social

Connect with experts and join the conversation about Radware technologies.

Blog
Security Research Center
CyberPedia