{"id":9997,"date":"2017-12-14T01:01:02","date_gmt":"2017-12-14T06:01:02","guid":{"rendered":"http:\/\/worldjusticenews.com\/news\/?p=9997"},"modified":"2017-12-14T01:02:16","modified_gmt":"2017-12-14T06:02:16","slug":"mirai-botnet-three-admit-creating-running-attack-tool","status":"publish","type":"post","link":"https:\/\/worldjusticenews.com\/news\/2017\/12\/14\/mirai-botnet-three-admit-creating-running-attack-tool\/","title":{"rendered":"Mirai botnet: Three admit creating and running attack tool"},"content":{"rendered":"<p>Late last year, a massive distributed denial of service (DDoS) against Dyn, a company that controls much of the internet\u2019s domain name system (DNS) infrastructure, caused disruption to online services worldwide.<\/p>\n<p>With millions of users unable to access major websites such as PayPal, Reddit and Twitter, this attack was likely the largest of its kind. Dyn\u00a0<a class=\"external\" href=\"http:\/\/dyn.com\/blog\/dyn-analysis-summary-of-friday-october-21-attack\/\" target=\"_blank\" rel=\"nofollow noopener\">reported\u00a0<\/a>that the attack was orchestrated using the Mirai Botnet and estimated that up to 100,000 malicious endpoints were involved.<\/p>\n<p class=\"story-body__introduction\">A US-based man has pleaded guilty to creating the giant botnet that was used to disrupt access to much of the web in October 2016.<\/p>\n<p>The Mirai malware also caused havoc later last year when it was used to stop people&#8217;s internet routers working.<\/p>\n<p>Paras Jha has admitted working with others to infect more than 300,000 devices and using them to carry out distributed denial of service (DDoS) attacks and other criminal activity.<\/p>\n<p>He has yet to be sentenced.<\/p>\n<p>Two other people &#8211; Josiah White and Dalton Norman &#8211; have also agreed to plead guilty to using the botnet for criminal gain.<\/p>\n<p>The details were revealed in documents filed in May but which have only now been unsealed by an Alaskan court.<\/p>\n<p>Security blogger Brian Krebs has\u00a0<a class=\"story-body__link-external\" href=\"https:\/\/krebsonsecurity.com\/tag\/paras-jha\/\" target=\"_blank\" rel=\"noopener\">published additional information stating<\/a>\u00a0that Jha is 21 years old and from New Jersey, while White is 20 years old and from Washington, Pennsylvania. The two used to run a company that marketed itself as a means to mitigate incoming DDoS attacks.<\/p>\n<p>According to the plea agreement, Jha admitted writing Mirai&#8217;s code in or about July 2016, before working with others to use it to flood targets against whom he had a grudge with internet traffic.<\/p>\n<p>The papers say he has also acknowledged renting the botnet to others for a fee, as well as using it to extort money from internet hosts and others by demanding payment to halt attacks.<\/p>\n<p>White has admitted adding scanning functionality to the code in August, allowing the malware to identify further vulnerable devices to infect.<\/p>\n<p>And in September, New Orleans-based Norman expanded the size of Mirai to more than 300,000 devices by helping the other two men take advantage of vulnerabilities they had not been aware of.<\/p>\n<p>In September or October, the documents say, Jha posted Mirai&#8217;s code online in an effort to create plausible deniability if his equipment was seized by the police.<\/p>\n<p>The botnet then grew further and was subsequently used against Dyn &#8211; a company that effectively provides the internet&#8217;s address books, making it possible for users to type in a website address and be connected to the computer servers holding the content they want.<\/p>\n<p>The result was that, for a time, many sites &#8211; including Reddit, Twitter, Amazon, Netflix and the BBC &#8211; became inaccessible to many visitors.<\/p>\n<p>The three men have not been accused of carrying out this attack themselves.<\/p>\n<p>Over the following months the malware was also used to expose a flaw present in millions of routers, preventing homes and businesses from connecting to the net.<\/p>\n<p>&#8220;Mirai will be seen in future as the first major botnet that used the growing army of the internet of things [IoT],&#8221; commented Prof Alan Woodward, a cyber-security expert at Surrey University.<\/p>\n<p>&#8220;It demonstrated just how vulnerable many of the cheap, internet-connected devices were to hackers who wanted to co-opt them to conduct massive attacks.<\/p>\n<p>&#8220;Derivatives of Mirai live on today, with new IoT devices often targeted to see if a new variant of the botnet can be recreated, presumably to cause an equal amount of disruption.&#8221;<\/p>\n<p>Under the terms of the plea, Jha faces up to 10 years in jail.<\/p>\n<p>That includes time\u00a0<a class=\"story-body__link-external\" href=\"http:\/\/www.nj.com\/education\/2017\/12\/rutgers_student_charged_in_series_of_cyber_attacks.html#incart_river_mobile_home\" target=\"_blank\" rel=\"noopener\">for separate attacks<\/a>\u00a0he carried out against Rutgers University&#8217;s internet network, which he has also admitted, as detailed by the New Jersey Ledger newspaper.<\/p>\n<p>Norman and White both face up to five years in prison.<\/p>\n<p>Source: <a href=\"http:\/\/www.bbc.co.uk\/news\/technology-42342221\" target=\"_blank\" rel=\"noopener\">bbc.co.uk<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\">Late last year, a massive distributed denial of service (DDoS) against Dyn, a company that controls much of the internet\u2019s domain name system (DNS) infrastructure, caused disruption to online services worldwide. With millions of users <a class=\"mh-excerpt-more\" href=\"https:\/\/worldjusticenews.com\/news\/2017\/12\/14\/mirai-botnet-three-admit-creating-running-attack-tool\/\" title=\"Mirai botnet: Three admit creating and running attack tool\">[&#8230;]<\/a><\/div>\n","protected":false},"author":1,"featured_media":9998,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","footnotes":""},"categories":[2,3],"tags":[4536,4539,1012,4538,4535,4537],"class_list":{"0":"post-9997","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-usa","9":"tag-botnet","10":"tag-dalton-norman","11":"tag-dyn","12":"tag-josiah-white","13":"tag-mirai","14":"tag-paras-jha","15":"pmpro-has-access"},"_links":{"self":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/9997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/comments?post=9997"}],"version-history":[{"count":3,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/9997\/revisions"}],"predecessor-version":[{"id":10001,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/9997\/revisions\/10001"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media\/9998"}],"wp:attachment":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media?parent=9997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/categories?post=9997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/tags?post=9997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}