Krebs Finds Mirai Botnet's Probable Authorship

2 min read
03 October 2022


The Mirai botnet caused a lot of problems in the fall of last year, first hijacking numerous IoT devices to create an historically huge Distributed Denial-Of-Service (DDoS) attack on KrebsOnSecurity's site in September before taking down an entire chunk of the internet one month later. But who is the person responsible for the malware? After his site was hacked, security researcher Brian Krebs went on a quest to determine the source of the malware, and he thinks that he has the answer: Multiple sources and evidence that support it point to Paras Jha, an Rutgers University student and owner of DDoS protection provider Protraf Solutions.
Mcname.Org



The source code for the Mirai botnet was released by the attacker, who went by Anna Senpai's name just a week after. This led to other copies of the attacks. It also gave Krebs with the first clue to the long road to discover Anna Senpai's true identity. Krebs created a glossary of terms and names with cross-references and a partial map of relationships.



The full report is admittedly lengthy and clocked at more than 8000 words, but it's worth the time to learn how botnet wranglers make money siccing their zombie device armies on unsuspecting targets. The sources that pointed Krebs to Anna Senpai's identity were involved in the use of botnets for the benefit of dark clients, releasing them on security firms that protect lucrative Minecraft servers that host thousands of gamers. Players will leave if their online gaming is affected, for example, by annoying DDoS attacks or repeated DDoS attacks. Servers are enticed to switch to security services who can offer protection, in this case, the same providers who orchestrated the botnet attacks.



Krebs sources claim that Krebs the security website was compromised in the botnet war through revealing information in September which led to the arrests of two hackers responsible for the Israeli "vDos" attack service. Anna Senpai was allegedly bribed to unleash Mirai on the KrebsOnSecurity site by angry customers who'd used the vDos service that's now gone which consolidated the security firm's interest.

In case you have found a mistake in the text, please send a message to the author by selecting the mistake and pressing Ctrl-Enter.
Hickman Falk 0
Joined: 1 year ago
Comments (0)

    No comments yet

You must be logged in to comment.

Sign In / Sign Up