43. IoT and OT Security – Cameras, Smart Devices, Plant Networks
43.4 Mirai-Class Botnets – Weak IoT, Outbound C2
Mirai (2016, public reporting): malware that guessed default / weak credentials on internet-facing IoT (cameras, routers, DVRs), then used the army for DDoS. October 2016 attacks on DNS provider Dyn caused wide service disruption for many sites; Dyn and partners reported Mirai-related traffic from a very large set of IPs (tens of millions of discrete addresses observed in the attack traffic, as Dyn stated – verify). Later U.S. cases involved people who created/shared Mirai code (public court reporting).
SME / ISP lessons for Blue:
- Your camera becomes someone else's cannon – outbound floods, not only inbound viewing
- ISP may cut your line; reputation of your public IP burns
- Fix = unique passwords, no WAN management, firmware updates, egress allow-lists for IoT VLAN
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Brute default Telnet/SSH on exposed IoT | No WAN Telnet; unique creds; vendor blocklists |
| Points botnet at a victim (DDoS) | Egress rate caps on IoT VLAN; detect odd outbound |
| Shares Mirai-class builders | Never download; IR + legal path if you find infection |
Ravindra Bagale's Tip
Students Mirai source GitHub var "research" mhantat. Aaplya book madhe nahi. Interview: "I harden IoT so it cannot join a botnet; I do not run botnet code." He lakshat theva.
Lab
Design-only: draw Sahyadri IoT VLAN – cameras → firewall → internet. Mark blocked outbound except NTP + vendor update HTTPS. 6 sentences on why "cameras need full internet" is usually false.
Real incident: Mirai and the Dyn DNS disruption (2016)
On 21 October 2016, Dyn's managed DNS infrastructure faced large, multi-wave DDoS events that disrupted access to many popular services for users in North America and Europe (widely reported). Dyn stated that analysis with partners (including Flashpoint and Akamai) confirmed Mirai-infected devices as a significant source, with attack traffic associated with tens of millions of IP addresses. Root weakness on the IoT side: devices with default or trivial credentials reachable from the internet. Defence for SMEs: change defaults, disable remote admin, patch, keep cameras off the open internet, watch egress. Source: Dyn public statements on the 21 Oct 2016 attack; major contemporaneous reporting (verify; say "reported" for scale).