Unsealed court documents show three men have plead guilty to creating the 2016 Mirai botnet that disrupted access to major internet platforms
doubling every 76 minutes. http://www.wired.com/... http://twitter.com/... Chris Bing / @bing_chris : ICYMI: the dude who created the Mirai botnet ran a DDoS mitigation service: http://krebsonsecurity.com/... http://twitter.com/... @briankrebs : The NJ Ledger just moved a story confirming my original reporting in January 2017, that Mirai co-author Paras Jha was responsible for the series of Mirai botnet attacks on Rutgers University, where he was a computer science undergrad student http://www.nj.com/...
Context & Ripple Effects
The guilty pleas land one day after unsealed court documents showed the US DoJ charging Paras Jha with co-creating the 2016 Mirai botnet, and they confirm reporting that Jha was behind the Mirai attacks on Rutgers University, where he studied computer science. Wired's account of the FBI investigation traces the malware back to its origins in DDoS attacks on Minecraft servers before it was turned loose on major internet platforms.
The pleas are not an endpoint: Wired later reported the government sought to keep the convicted Mirai authors working with the FBI as part of their sentencing, and IEEE Spectrum's retrospective shows all three avoided prison by helping federal cybercrime efforts.
First-order effects
- Sentencing now hinges on cooperation rather than custody — Jha and his co-defendants' value to investigators becomes the currency that determines their punishment, with Rutgers attack liability attached specifically to Jha.
- The DoJ gains named, convicted botnet authors whose operational knowledge of Mirai's infrastructure can be turned against active threats.
Second-order effects
- The FBI's push to continue working with the Mirai hackers after conviction establishes cooperation-as-sentencing as a template prosecutors can reuse on future young malware developers.
- Mirai's method of conscripting insecure IoT devices puts device makers and platform operators under pressure to harden default credentials, since the same attack surface remains open to the next botnet.
Third-order effects
- If the pattern holds, the DoJ's handling of Mirai foreshadows a standing pipeline that converts talented malware authors into government cybercrime assets instead of prison populations — a model visible again in the 2025 DanaBot charges against 16 alleged operators.
- Sustained botnet prosecutions built on IoT exploitation give regulators a concrete harm record to justify mandatory security baselines for connected consumer devices.
The trend: Botnet prosecution is evolving from punishment toward co-option, with the DoJ repeatedly trading prison time for the operational expertise of the very people who built the malware.