VideoCybersecurity

A reference for securing video infrastructure

What Mirai did to the camera industry

A reading of the Mirai court record — what the defendants signed for, and which of the famous numbers came from somewhere else.

Published 5 September 2026Sources 14

Paragraph 6 of the federal Information charging Paras Jha sets out what separated Mirai from the botnet malware before it: it targeted "the 'Internet of Things' ('IoT') — non-traditional computing devices that have been connected to the Internet, including wireless cameras, routers and digital video recorders." Cameras and DVRs are named in the charging instrument itself.

Three defendants, three dockets#

The prosecutions are usually described as one case, three men, one count each. The docket is untidier. Jha, Josiah White and Dalton Norman each faced a parallel Mirai conspiracy Information in the District of Alaska — 3:17-cr-00164, 3:17-cr-00165 and 3:17-cr-00167 — charging conspiracy to violate 18 U.S.C. § 1030(a)(5) in violation of § 371. White pleaded to the sole count of his own Information and nothing else. Jha and Norman each pleaded to a second CFAA conspiracy count in a separate Alaska clickfraud case, 3:17-cr-00163, and Jha pleaded guilty again in the District of New Jersey for the Rutgers attacks. "A single count" describes White alone.

The stated object of the conspiracy has nothing to do with surveillance. White's and Norman's factual bases run the same two-part formula: the botnet existed to "create a weapon capable of initiating powerful denial of service attacks" against business competitors and people the conspirators held grudges against, and to earn money by renting that weapon out and by extorting "hosting companies and others into paying protection money." Cameras appear in the record as the population the scanner found. No filing says why that population.

White's overt acts carry the operational texture. He created the scanner in August 2016 — it works "by scanning the internet for devices that respond on a given port number, and then attempting to gain unauthorized administrative access to those devices by entering a series of login credentials" — and used it the same month. In September he "directed and oversaw the repositioning of the Mirai C2 server to the hosting provider BackConnect." Norman admitted the other half of the growth problem: in September 2016 he identified "vulnerabilities for thousands of IoT devices," many of them "private zero-day vulnerabilities, meaning vulnerabilities that had not yet been disclosed," sourced that way so the operators would not have to compete with other criminals for the same devices. The default-password worm of popular memory is one component of what was charged.

Which numbers were admitted and which were estimated#

FigureWhat it countsWhere it comes fromStanding
Over 300,000Devices that became part of the botnetJha Information overt act (a); the Jha and Norman plea agreementsAdmitted under oath
"hundreds of thousands"Devices infected with MiraiWhite and Norman plea factual basesAdmitted under oath
515,000+Systems showing signs of the vulnerable XiongMai hardware, scanned 6 October 2016Flashpoint, reported by KrebsPrivate research, reported contemporaneously
500,000+, 600,000+Devices ever infectedPress coverageResearcher estimate

A single filing can shift its own units. Norman's factual basis says the conspirators "successfully infected hundreds of thousands of internet-connected computing devices"; overt act (a) of that same document says "Over 300,000 devices ultimately became part of the Mirai botnet." The larger counts in circulation measure something else again — devices ever infected across the botnet's life rather than devices enrolled in it, and the two definitions have never been publicly reconciled.

The credential and the vendor#

On the day of the Dyn outage, Brian Krebs reported Flashpoint's finding that Mirai's default credential root/xc3511 was hardcoded into white-labeled DVR and IP-camera boards made by Hangzhou XiongMai Technologies, and that a scan on 6 October 2016 had found more than 515,000 systems showing signs of that hardware. Allison Nixon of Flashpoint, quoted the same day: "It's remarkable that virtually an entire company's product line has just been turned into a botnet that is now attacking the United States." None of the filings quoted here names XiongMai. The attribution is credible contemporaneous reporting of a private research finding, never restated in a government determination.

The mechanism is the part worth carrying forward. That credential was hardcoded in firmware behind Telnet and SSH, and could not feasibly be changed from the device's web admin panel — the surface where an installer would look for it. DVR security covers where that architecture persists.

XiongMai answered on 24 October 2016 with three things at once: a promised recall, mainly of network cameras; a dispute of how its products had been characterised; and a threat of legal action against Western publications over "false statements". Its statement to media said devices shipped after September 2015 had Telnet disabled by default. Krebs noted that the company's Chinese-language statement gave April 2015 instead.

What is not documented#

Vendor-side response to 2016 is thin in the record, and saying so is more useful than filling it in. For the ODM and white-label tier — the XiongMai class of board — no security documentation could be located at all: nothing on firmware signing, nothing on secure boot, no advisory series. That is not proof the features are missing, but it does leave a buyer no way to check — and this is the tier where CISA's "discontinue utilization of the product" required actions concentrate. What the branded vendors publish about firmware integrity, and how much of it survives an unsigned first boot stage, is covered in camera firmware and the patching problem.

Regulation is under-verified here too. The FCC's Covered List page rejects automated fetchers, so the statutory wording under which Hikvision and Dahua video surveillance equipment is listed, and the listing dates, are not confirmed against the primary source on this page; procurement rules that now govern surveillance equipment sets out what is established.

The technique after ten years#

FortiGuard Labs reported on 6 December 2021 that Moobot — "a DDoS botnet based on Mirai" — was being delivered through CVE-2021-36260, the unauthenticated command injection in Hikvision's web server, roughly eleven weeks after the researcher published on 18 September 2021. Fortinet gave no count of compromised devices; write-ups that attach one are supplying it. On 18 September 2024 an FBI/CNMF/NSA joint advisory described a botnet run by the PRC-linked Integrity Technology Group that "uses the Mirai family of malware, designed to hijack IoT devices such as webcams, DVRs, IP cameras, and routers running Linux-based operating systems," listing CVE-2021-36260 in Appendix B among the CVEs used to add devices. As of June 2024 it held over 260,000 devices, broken out by country and processor architecture only — any camera share of that total is an extrapolation.

Credential guessing never needed replacing. In a 35-day campaign ending 22 July 2026, the largest share of the Dahua compromises documented by Hunt.io came from credential brute-force on TCP 37777 — White's August 2016 method, pointed at a different vendor's management port. The full vector breakdown is in how cameras become internet-exposed.

CISA's KEV catalog at version 2026.09.04 holds 22 entries that resolve to a video product, across vendors including Hikvision, Dahua, NUUO, GeoVision, Reolink, Edimax, Amcrest, TVT, QNAP VioStor and Digiever. Not one is flagged as used in a known ransomware campaign. Command injection and missing or improper authentication dominate; memory corruption is the minority class. Whether the ransomware absence reflects the real exploitation pattern or a hole in CISA's attribution data for embedded devices is undetermined. What the catalog measures unambiguously is dwell: CVE-2017-7921, a Hikvision improper-authentication flaw NVD published on 6 May 2017, was added to KEV on 5 March 2026 — eight years and ten months — against firmware builds dating to 2014.

The installed base has not thinned out. A DHS Office of Intelligence & Analysis bulletin dated 3 February 2025 describes "tens of thousands of PRC-made cameras on the networks of US critical infrastructure entities" and records growth of up to 40 percent between 2023 and 2024 despite the FCC import ban. CISA identified likely white-labeled PRC-manufactured cameras at over 100 US federal, state, local, tribal and territorial government and critical infrastructure entities in 2022, and at least four US oil and gas entities had such cameras networked to OT systems as of December 2022. Its most-quoted figure is its weakest: the early-2024 estimate of 12,000 PRC-manufactured cameras at hundreds of US critical infrastructure entities comes from an unnamed US cybersecurity firm — a commercial estimate carried inside a government document.

Dates#

DateEventSource class
Aug 2016White creates the Mirai scanner and uses itPlea agreement
Sep 2016Norman sources private zero-days; C2 repositioned to BackConnectPlea agreements
6 Oct 2016Flashpoint scan: 515,000+ systems showing signs of the vulnerable hardwarePrivate research, reported
21 Oct 2016Dyn DDoS; cameras and DVRs implicated the same dayContemporaneous reporting
24 Oct 2016XiongMai recall promise and legal threatVendor statement
5 Dec 2017Charging documents and plea agreements filed in D. AlaskaCourt record

What the record leaves open#

Overt act (8) of Jha's plea agreement dates his public posting of the Mirai source code to "In or about September and October 2017." The contemporaneous record puts that posting on 30 September / 1 October 2016, and nothing in the document resolves whether the filing carries a typographical error; the quote is only safe with that caveat attached. The same agreement never mentions the 21 October 2016 Dyn attack, though its date range does not exclude it. It does give Jha's own account of why he published: he "posted the Mirai code online, in order to create plausible deniability if law enforcement found the code on computers controlled by Jha or his co-conspirators."

The other open item belongs to the vendor. XiongMai's recall was announced on 24 October 2016, and no primary source available for this page establishes what it covered or whether it finished. That announcement is one of very few occasions on which a video-component OEM has publicly acknowledged a botnet role at all. A decade later it is still only a press statement.

Sources

  1. United States v. Paras Jha, Information (Felony), D. Alaska No. 3:17-cr-00164-TMB, Doc. 1. U.S. District Court for the District of Alaska (via CourtListener RECAP), 2017-12-05
  2. United States v. Paras Jha, Plea Agreement, D. Alaska No. 3:17-cr-00164-TMB, Doc. 5. U.S. District Court for the District of Alaska (via CourtListener RECAP), 2017-12-05
  3. United States v. Josiah White, Plea Agreement, D. Alaska No. 3:17-cr-00165-TMB, Doc. 5. U.S. District Court for the District of Alaska (via CourtListener RECAP), 2017-12-05
  4. United States v. Dalton Norman, Plea Agreement, D. Alaska No. 3:17-cr-00167, Doc. 5. U.S. District Court for the District of Alaska (via CourtListener RECAP), 2017-12-05
  5. Source Code for IoT Botnet 'Mirai' Released. Krebs on Security, 2016-10-01
  6. Hacked Cameras, DVRs Powered Today's Massive Internet Outage. Krebs on Security, 2016-10-21
  7. IoT Device Maker Vows Product Recall, Legal Action Against Western Accusers. Krebs on Security, 2016-10-24
  8. Hikvision IP Camera Unauthenticated RCE (CVE-2021-36260). watchfulip, 2021-09-18
  9. Mirai-based Botnet — Moobot Targets Hikvision Vulnerability. FortiGuard Labs, 2021-12-06
  10. People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations (JCSA-20240918-001). FBI / CNMF / NSA, 2024-09-18
  11. Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia. Hunt.io, 2026-08-18
  12. Known Exploited Vulnerabilities catalog (catalogVersion 2026.09.04). CISA, 2026-09-04
  13. CVE-2017-7921 record. NVD, NVD published 2017-05-06
  14. (U//FOUO) People's Republic of China: Exploitation of Internet-Connected Cameras Threatens US Critical Infrastructure, DHS-IA-IF-2025-02684. DHS Office of Intelligence & Analysis, 2025-02-03