1. https://www.flashpoint-intel.com/mirai-botnet-linked-dyn-dns...
2. https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with...
3. https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...
1. https://www.flashpoint-intel.com/mirai-botnet-linked-dyn-dns...
2. https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with...
3. https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...
So not quite.
> Dale Drew, chief security officer at Level 3, an internet service provider, found evidence that roughly 10 percent of all devices co-opted by Mirai were being used to attack Dyn’s servers. Just one week ago, Level 3 found that 493,000 devices had been infected with Mirai malware, nearly double the number infected last month.
http://www.nytimes.com/2016/10/22/business/internet-problems...
If they aren't significantly underestimating the number of devices participating in this attack, it paints an ugly picture of things to come. My understanding is these botnets are almost impossible to eradicate due to how fast/easy it is to re-compromise the devices, so traditional methods of taking out C2s do almost nothing. Bonus - Mirai source code is freely and easily available for skids to use now, so there's no single threat actor for attribution/retaliation/arrest/etc.
Although the source code is out there, those will not be able to control all those devices.
“The issue with these particular devices is that a user cannot feasibly change this password,” Flashpoint’s Zach Wikholm told KrebsOnSecurity. “The password is hardcoded into the firmware, and the tools necessary to disable it are not present.
- https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...
That's not to say it couldn't flash the devices but I don't recall seeing that capability in the Mirai source and haven't read about it doing so.