
Minecraft is perhaps the most popular modern video game. There is no ultimate goal in it, the graphics in the game deliberately old -fashioned, but in Minecraft you can build anything. At the same time, more than a million people play it, and the monthly audience exceeds 55 million. The game itself is inexpensive, but online servers for a joint game offer additional services for money: for example, priority access, the ability to fly and the like bonuses. Many servers allow you to play a highly modified Minecraft, which has little in common with the original game. The main audience of the game is children.
Successful business on servers at Minecraft can bring up to 100 thousand dollars per month. Together with the servers, there is a separate DDOS attack market on them: for a small fee you can temporarily “fill up” the co-competing server with garbage traffic, slow down the game on it and simply disable. By 2016, this type of “business” was slowly dying: there were many services that offered cheap protection against DDOS attacks for servers in Minecraft.
The 21-year-old student from New Jersey Paras JJ and his peers from Pittsburgh and New Orleans Josias White and Dalton Norman began to think how to make money on DDOS attacks and decided to create their own company that would protect these attacks. This is a common practice in the world of cybercrime: people who offer protection often before that they themselves break the client. They came to create a program that herself would look for devices such as routers, webcams, printers with access to the network, even refrigerators and toasters with Wi-Fi-and would take control of them.
In such devices, logins and passwords are extremely rarely changed, most often it is something like “admin/admin”. They have many vulnerabilities that no one closes, unlike “holes” in large operating systems. The owners of such devices do not notice anything, for them it works as before. Norman was engaged in the search for such vulnerabilities, and Jah and White created a mechanism for searching for devices and spreading a malicious program. The speed with which Mirai infected devices around the world turned out to be amazing: in the first day of work, Botnet had about 70 thousand devices, and then grew to 600 thousand.
On September 19, 2016, the creators of Mirai for the first time seriously demonstrated the power of their cyber weapons and attacked the French hoster OVH. The solution was purely pragmatic: many owners of servers for Minecraft paid OVH for protection against DDOS attacks, and the creators of Mirai wanted to show the unreliability of the service and earn money, offering their services. OVH came up with DDOS attacks daily and knew how to effectively defend them, but he also saved before Mirai. Botnet of hundreds of thousands of zombie devices drove more than 1 terabitis per second. This is ten times more than in the largest DDOS attacks in the past. Mirai immediately attacked the entire OVH network, and not individual IP addresses and sites, which made it even more dangerous.
A few days later, Mirai attacked the blog of a computer security specialist Brian Krebs, who recently wrote about the DDOS-Atak of the creators of Mirai. As a result, his site did not work for four days despite the fact that he was protected by the service from such attacks.
A little later, at the end of September, the authors of Mirai uploaded the source code into open access - they thus wanted to protect themselves from criminal prosecution, because when the source code is available, anyone can use cyber weapons, and not just the creators. After that, on October 21, 2016, the largest in the history of DDOS attacks occurred. DNS Dyn Registrar, which provides a connection between what you enter into the browser line, and the IP address of the site you need, fell under the yard of garbage traffic. The New York Times failed, Spotify, Twitter, Netflix and many other services and sites stopped working; Basically, problems affected the east coast of the United States. Who exactly attacked Dyn is still unknown: these were not the creators of Mirai, but someone who took advantage of the source code of the program.

The search for the creators of Mirai was engaged in the FBI management located in Alaska. A small team of four people in Anchoridge specialized in botnets and DDOS attacks primarily because the sparsely populated Alaska is highly dependent on the Internet, and interruptions in relations can lead to serious consequences. The agents became interested in the fact that Mirai was used against Minecraft servers, and that all the well -known attacks that occurred before the publication of the source code were somehow connected with this game. At first, the agents were sure that they found the creator of Mirai in France: their searches led to the computer of a French teenager, a passionate anime; He was innocent.
In January 2017, Brian Krebs suggested that Americans Paras Jah and Josia White can be related to the creation of Mirai. His conclusions were confirmed by the FBI team in Alaska, they also found out the name of their accomplice. As follows from the conclusions of the investigation, they still wanted to earn on their creation, so after DDOS attacks they came up with another use. Hackers created a botnet of 100 thousand devices and forced them to click on advertising links, simulating the behavior of real users - and thereby deceiving advertisers.
On Friday, December 8, Jia, White and Norman pleaded guilty to the creation of Mirai.
Two weeks ago, at the very beginning of December, a new botnet appeared from devices connected to the Internet, created on the basis when Mirai. It is called Satori, in the first 12 hours of work a quarter of a million devices were infected (English).