Overview
Mirai scanned the entire IPv4 space for Telnet-exposed cameras, routers and DVRs, logging in with roughly sixty factory-default username and password pairs.\nIt powered the attack that took Dyn, and with it much of the North American internet, offline.\nThe source code was published, so variants still circulate years later.\nChanging default credentials and closing Telnet is the whole mitigation.
Indicators of Compromise
Signals that suggest this is present on a system.
- Telnet open to the internet
- Factory-default logins succeeding
- Devices joining outbound botnet command channels