Mirai botnet did not knock Liberia's internet offline, say security experts

West African country didn't suffer nationwide outage last week, contrary to reports

Security experts have dismissed last week's reports that Liberia's entire internet infrastructure was taken down by a DDoS attack, stating that this story was "simply not true".

Despite widespread coverage, the claims were debunked by security expert Brian Krebs who found that contrary to reports, the attack did not cause a nationwide outage. He spoke to Daniel Brewer, general manager for the Cable Consortium of Liberia, who told him that "we have no knowledge of a national internet outage and there are [sic] no data to [substantiate] that."

Advertisement - Article continues below

The reports stemmed from security architect Kevin Beaumont, who noticed attacks on Liberian telecoms infrastructure while monitoring the activity of the Mirai botnet. He apparently spoke to an anonymous source withing a local telco, who supposedly confirmed that the country's single submarine internet cable - which Beaumont pointed to a "single point of failure" - was under 500Gbps attacks.

"From monitoring, we can see websites hosted in country going offline during the attacks," he wrote. "Additionally, a source in country at a Telco has confirmed to a journalist they are seeing intermittent internet connectivity, at times which directly match the attack."

Many news outlets (including IT Pro) took this to mean that the internet connection for the whole country was under threat, but Brewer emphatically confirmed that this was not the case, stating "both our ACE submarine cable monitoring systems and servers hosted (locally) in LIXP (Liberia Internet Exchange Point) show no downtime in the last 3 weeks."

Advertisement - Article continues below
Advertisement - Article continues below

It appears that the attacks observed by Beaumont were in fact mounted against a mobile telco; one that had a DDoS mitigation service in place to minimise the effects of the attack. While local web performance may have been intermittent, it was decidedly not a nationwide issue.

This was confirmed by cloud and security company Akamai as well as Dyn, the DNS provider that was hit by a much bigger DDoS last month. The company's director of internet analysis tweeted that there was no evidence of any widespread problems.

However, security expert Graham Cluley cautioned that although the Liberian incident was not as bad as initially thought, Mirai and other IoT-based malware still poses a significant threat.

"None of this is to say Mirai that is not a serious threat, of course," he wrote, "and that new botnets based upon its leaked code don't pose a significant threat to internet infrastructure as they exploit poorly-protected IoT devices."

Featured Resources

Navigating the new normal: A fast guide to remote working

A smooth transition will support operations for years to come

Download now

Putting a spotlight on cyber security

An examination of the current cyber security landscape

Download now

The economics of infrastructure scalability

Find the most cost-effective and least risky way to scale

Download now

IT operations overload hinders digital transformation

Clearing the path towards a modernised system of agreement

Download now


web browser

Microsoft will start forced updates for education and business devices this month

3 Jul 2020

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020
cloud security

CSA and ISSA form cyber security partnership

30 Jun 2020

Most Popular


How to find RAM speed, size and type

24 Jun 2020
data protection

EU institutions told to avoid Microsoft software after licence spat

3 Jul 2020

Microsoft releases urgent patch for high-risk Windows 10 flaws

1 Jul 2020