Hackers are using Mirai-based botnets to DDoS the domain hardcoded into WannaCry in an attempt to reduce effectiveness of the kill-switch, revive the ransomware
Over the past year, two digital disasters have rocked the internet. The botnet known as Mirai knocked a swath of major sites off …
Context & Ripple Effects
Mirai stopped being a single botnet when its source code was publicly released on Hackforums in October 2016 — since then, copycat operators have run it against the DNS provider behind the DynDNS outage and tried to conscript routers belonging to Deutsche Telekom, TalkTalk and Post Office customers, disrupting access for over a million people.
The new twist reported here is targeting: instead of attacking a victim site or harvesting devices, a Mirai-based botnet is being pointed at the hardcoded WannaCry kill-switch domain itself, trying to make the failsafe unreachable so the ransomware keeps encrypting.
First-order effects
- Whoever controls the kill-switch domain — the researchers who sinkholed it — is now under sustained DDoS pressure, and every infected machine that cannot resolve the domain stays live and continues spreading WannaCry.
Second-order effects
- Defenders have to harden or duplicate kill-switch infrastructure rather than rely on a single hardcoded domain, while the same pool of hijacked consumer routers and XiongMai-component DVRs and cameras from the Dyn era becomes an off-the-shelf weapon for any campaign.
Third-order effects
- If leaked malware source keeps getting forked this way, botnet capability becomes reusable commodity infrastructure rather than a one-off operation, pushing incident response toward resilient, decentralized sinkholing and adding weight to calls for baseline security in consumer IoT devices.
The trend: Publicly released malware source code is turning botnets like Mirai into commodity attack infrastructure that each new campaign — from DDoS extortion to ransomware revival — can rent or rebuild.