Mirai first became famous for knocking parts of the internet offline in 2016. You’d think something that old would be yesterday’s problem. It isn’t. The basic idea behind Mirai still works because huge numbers of internet-connected devices are badly protected, and attackers keep finding new ways to use them.

The Problem Is Bigger Than Mirai Itself

Mirai targets connected devices such as cameras and routers. Many sit online for years without much attention from their owners. Some still have weak login details. Others run old software that nobody bothers to update.

And that’s where Mirai’s real staying power comes from. The original malware became public, and its source code was leaked online. That gave other criminals a starting point they could change and reuse instead of building a botnet from scratch.

Old Code, New Tricks

Modern Mirai-based malware doesn’t need to look exactly like the original version. Attackers have modified the code to target different devices and exploit newer weaknesses. Some versions also use different methods to spread or hide what they’re doing.

The annoying part is how little effort is needed from the victim. A person might buy a cheap connected camera, plug it in, and forget about it. The device keeps running in the corner of the room while attackers search the internet for exposed systems.

IoT Devices Make Easy Targets

A laptop usually gets attention. You notice updates. You install security software. A random camera mounted above a shop entrance? Not so much.

That assumption is exactly what attackers like.

• Cheap hardware often stays connected for years, even after the software becomes outdated.

• Weak passwords are still a problem, especially on devices that were installed quickly and then forgotten.

• The device itself might look harmless, but a compromised camera or router can become part of a much larger botnet.

One Device Can Join Thousands

Mirai’s strength comes from scale. One infected device isn’t especially impressive. Thousands of them are different.

Once attackers control enough devices, they can use that combined network to overwhelm a target with traffic. That can turn into a distributed denial-of-service attack, commonly called a DDoS attack. The target gets flooded from many different devices at once, making the traffic harder to block.

Why It Still Matters Today

The bigger concern is that Mirai helped prove a business model. IoT devices could be hijacked at scale, and the same basic approach could be adapted as technology changed.

Security researchers continue to see Mirai-related activity because vulnerable connected devices haven’t disappeared. In fact, there are more kinds of connected equipment now, which gives attackers more places to look.

The Real Weakness Is Often Forgotten Hardware

Mirai remains dangerous because its core lesson still applies. A device doesn’t need to be powerful or important to become useful to an attacker. It only needs to be connected and poorly protected.