Most cybercriminals shelter behind menacing pseudonyms. Kenneth Currin Schuchman chose two — “Nexus” and “Nexus-Zeta” — and then registered his botnet’s command server under a Gmail address, nexuczeta1337@gmail.com, that pointed back to a “Kenny Schuchman” of Vancouver, Washington. Mr Schuchman, 21, has now pleaded guilty to one federal count of aiding and abetting computer intrusions, admitting his role in Satori, a botnet assembled from hacked internet-of-things (IoT) devices.

According to his plea agreement, between July 2017 and October 2018 Mr Schuchman conspired with at least two others, known online as “Vamp” and “Drake”, to build and deploy Satori in large-scale denial-of-service attacks: floods of junk traffic that left targets unreachable by legitimate visitors. The marks were internet service providers, online gaming platforms and web-hosting companies. The weapon was the pooled bandwidth of about 100,000 hacked devices, enslaved through vulnerabilities in wireless routers, digital video recorders, internet-connected security cameras and fibre-optic networking gear.

Mirai’s unruly children

Satori began life as a remix of the leaked source code for Mirai, the IoT botnet that appeared in the summer of 2016 and carried out some of the largest denial-of-service attacks ever recorded — including a 620-gigabits-per-second assault that took the KrebsOnSecurity blog offline for almost four days. Through 2017 and into 2018 Mr Schuchman and his partners kept finding and exploiting fresh flaws in other IoT systems, rechristening their creations “Okiru” and “Masuta” with almost every improvement. At their height the variants infected up to 700,000 compromised systems.

The object of the conspiracy, the plea agreement states, was to sell access to the botnets to others wishing to rent them for attacks — though how far the trio succeeded is unclear. Mr Schuchman’s conduct after his indictment in August 2018 was not that of a chastened man. While on supervised release he built a new botnet variant. He also fell out with Drake, and later acknowledged using information gleaned by prosecutors to identify his erstwhile partner’s home address.

That was the prelude to a “swatting”: a false report of violent mayhem — a hostage situation, a bomb threat, a murder — designed to send a heavily armed police response to a victim’s door. The call Mr Schuchman set in motion in October 2018 produced “a substantial law enforcement response at Drake’s residence”, according to the plea agreement.

The tradecraft elsewhere was no better. Beyond the telltale domain — originally registered to a “ZetaSec Inc.” as well as to Mr Schuchman himself — the constant scanning that keeps such botnets fed with new victims drew abuse complaints from internet providers. Mr Schuchman answered them in his father’s identity. The plea agreement states it flatly:

Schuchman frequently used identification devices belonging to his father to further the criminal scheme.

The brains, it seems, were elsewhere

Mr Schuchman may be the first person to plead guilty over Satori and its progeny, but those familiar with the case rank him low among its villains. Multiple sources tell KrebsOnSecurity that Vamp is a British resident who was principally responsible for coding Satori, and that as a minor he was involved in the 2015 hack of TalkTalk, a British phone and broadband provider. The same sources say Vamp was principally responsible for the enormous 2016 attack on Dyn, a firm providing core internet services for big-name websites, which on October 21st that year caused outages at Twitter, Spotify, Reddit and others.

The investigation is being run out of the Federal Bureau of Investigation’s field office in Alaska, spearheaded by some of the same agents who helped track down the original co-authors of Mirai and secure their guilty pleas. For Mr Schuchman — reportedly diagnosed with Asperger syndrome and autism — the single count carries a maximum of 10 years in prison and fines of up to $250,000. His plea deal points somewhere much softer: he agreed to a recommended sentence “at the low end of the guideline range as calculated and adopted by the court.”

Botnet cases have a habit of ending this way: the careless sign-up in the dock, the true author still a nickname in a chat log. The real defendants, meanwhile — millions of unpatched routers and cameras — remain at large, waiting for the next Mirai to recruit them.