Brian Krebs accuses founder of DDoS mitigation provider ProTraf Solutions as co-author of Mirai IoT worm; founder denies involvement
On September 22, 2016, this site was forced offline for nearly four days after it was hit with “Mirai,” a malware strain that enslaves poorly secured Internet of Things …
Context & Ripple Effects
Mirai first surfaced publicly when it knocked KrebsOnSecurity offline in September 2016, then escalated after a Hackforums user released its source code, letting anyone spin up copycat botnets — including the one behind the October DynDNS outage that took down chunks of the internet. With this report, Brian Krebs moves from victim to investigator: he names the founder of ProTraf Solutions, a DDoS mitigation provider, as an alleged co-author of the worm, and the founder denies it.
First-order effects
- ProTraf Solutions' founder now faces public allegations that he helped build the very malware his company's mitigation business profits from defending against — an immediate trust problem with existing and prospective customers.
- Krebs, who has spent roughly two decades exposing cybercriminals and has previously walked back coverage under pressure (his Ubiquiti apology after reporting blamed him for billions in lost market cap), again carries the risk of naming the wrong person.
Second-order effects
- Attribution does not contain the malware: because the source code was publicly released, Mirai derivatives kept operating independently — powering the DynDNS outage and later the attacks on WannaCry's kill-switch domain — so naming an author changes the legal and reputational picture without shrinking the botnet population.
- Vendors of the DVRs, cameras, and other unsecured devices Mirai enslaves face renewed scrutiny over default credentials and patching, since each new attribution story re-centers attention on how easily their products are conscripted.
Third-order effects
- If researchers keep converting anonymous botnets into named defendants, the industry moves toward personal legal accountability for malware authorship — and toward regulators treating insecure IoT devices as critical infrastructure rather than consumer gadgets.
- The episode also sharpens a structural tension in security journalism: single-investigator outlets like KrebsOnSecurity can force billion-dollar reputational consequences, which raises the stakes of every accusation and the cost of getting one wrong.
The trend: IoT botnet attribution is shifting from anonymous malware strains to named individuals, forcing device makers, mitigation firms, and security journalists into a new accountability loop.