PARAS JHA▊
A Rutgers computer-science student named his botnet after a cartoon, pointed it at the video-game servers he was trying to muscle out of business, and accidentally built the largest thing of its kind the internet had ever seen. When it took down the reporter who covered the scene — a record attack that got Brian Krebs kicked off his own free protection — the reporter came looking, and found "Anna-Senpai" hiding behind an anime handle, a Minecraft protection racket, and a résumé that matched line for line. Jha posted a denial. Eleven months later he pleaded guilty. He never saw the inside of a prison; he saw the inside of an FBI field office, as a consultant.
- WHO
- Paras Jha — "Anna-Senpai" / "dreadiscool" / "ogmemes123123," of Fanwood, New Jersey; Rutgers University computer-science student FACT
- CREW
- Co-authored Mirai with Josiah White ("LiteSpeed," Washington, PA) and Dalton Norman (Metairie, LA); ran the DDoS-mitigation firm ProTraf Solutions
- THE DRAMA
- Named the botnet for the anime Mirai Nikki, used it in Minecraft-server turf wars, took down KrebsOnSecurity at record scale — then denied it in the reporter's face before pleading guilty
- RECORD
- Guilty pleas, District of Alaska (Dec 2017): Mirai conspiracy + click-fraud conspiracy. Separate guilty plea, District of New Jersey: the Rutgers DDoS attacks (CFAA). Sentenced 2018 — no prison: probation, 2,500 hours community service, $8.6M restitution to Rutgers FACT
- STATUS
- COOPERATOR — the government credited "extraordinary cooperation"; the kid who broke the internet spent his sentence helping the FBI catch other people who do
This is not a manual and it is not a morality play. It is the record of what happens when a talented college student treats a video game like a market, builds a weapon to corner it, and discovers the weapon is bigger than the market — bigger, briefly, than the reporters and the hosting companies and one Friday's worth of the American internet. The through-line is the gap between the swagger — the anime handle, the "I made my money" farewell, the public denial — and the paperwork, which shows three college kids, a Minecraft protection racket, and a guilty plea.
the drama timeline
ACT I — THE MINECRAFT MARKET (2014–2016)
A profitable little corner of the internet — Minecraft servers pulling tens of thousands of dollars a month — turns into a turf war, and a college kid decides to sell everyone an umbrella after arranging the rain.
-
2014–16
ProTraf and the protection racket
Jha and Josiah White run ProTraf Solutions, a firm that sells popular Minecraft servers protection against denial-of-service attacks. Per rival operator Robert Coelho of ProxyPipe, the "lelddos" crew — which he tied to ProTraf's owners — hammered competing services offline so their customers would migrate to ProTraf. Attack the market, then sell it the cure. "In 2015, the ProTraf guys hit us offline tons, so a lot of our customers moved over to them," Coelho told Krebs.
-
2015–16
The Rutgers grudge attacks
Rutgers — where Jha was enrolled — is knocked offline by a string of DDoS attacks that fall across registration windows and exams. An attacker using "exfocus" and "og_richard_stallman" brags about it on Reddit and Twitter. Jha would later admit in a New Jersey federal plea that he was behind it; prosecutors said he launched one attack to delay registration for a computer-science class he wanted, another to disrupt his own calculus exam, and later ones for the publicity.
-
2016
Mirai, named for a cartoon
Jha, White, and Dalton Norman build Mirai — malware that trawls the internet for cameras, routers, and DVRs left on factory-default usernames and passwords and conscripts them into a botnet. They name it after the 2011 anime Mirai Nikki. In a leaked chat the author is blunt about it: "i rewatched mirai nikki recently — (it was the reason i named my bot mirai lol)." At its peak Mirai commanded roughly 300,000–380,000 hijacked devices.
ACT II — THE WEAPON GETS AWAY FROM THEM (SEPT–OCT 2016)
The thing built to win a game about blocks takes down a French hosting giant, a journalist, and then a chunk of the American internet — and the author panics and burns the evidence in public.
-
SEP 20, 2016
620 Gbps — Krebs goes dark
KrebsOnSecurity — which had just published on the vDOS booter service (see vDOS) — is hit by a then-record 620 Gbps attack from Mirai. Akamai, which had shielded the site pro bono for four years, said staying would cost millions and gave Krebs about two hours to leave. The site went dark for days until Google's Project Shield took it in. In a chat, Anna-Senpai clocked the fallout in real time: "but then krebs tweeted that akamai is kicking them off — fuck me — he was a cool guy too, i like his article."
-
SEP–OCT 2016
OVH, then Dyn
Around the same time the French host OVH takes an even larger Mirai assault, also traced to a Minecraft grudge. Then on October 21, 2016, a Mirai-family attack on the DNS provider Dyn stutters or stops much of the eastern-US internet — Twitter, Netflix, Reddit, and more — and briefly stokes fears of a nation-state dry run before an election. It was three college kids and a video game.
-
OCT 1, 2016
"Time to GTFO" — the source dump
With "lots of eyes looking at IOT now," Anna-Senpai posts the full Mirai source code to Hackforums — a classic move to salt the field so any future arrest can't pin the code to one author. It worked as cover and backfired as evidence: releasing it seeded copycats and left a signed farewell for investigators to read.
ACT III — THE UNMASKING (JAN 2017)
The reporter whose site got flattened does the thing reporters do. The trail runs through an anime-watchlist, a résumé, and an obscure programming language — straight to a Rutgers dorm.
-
JAN 17, 2017
"Who is Anna-Senpai?"
Krebs publishes a long forensic thread tying "Anna-Senpai" to Jha through the "dreadiscool" handle, a MyAnimeList profile that lists Mirai Nikki, a father-registered vanity domain with Jha's résumé, and a skills list — including the unusual language Go, which Mirai's control server was written in — that matched Jha's own LinkedIn. Anna-Senpai's boast on Hackforums ("I have 8 years of development under my belt... ASM, C, Go, Java, C#, and PHP") lined up almost exactly.
-
JAN 19, 2017
The denial
Jha responds to Krebs and denies everything: he says he did not write Mirai and did not attack Rutgers, and adds — of the case against him — "I don't think there are enough facts to definitively point the finger at me. Besides this article, I was pretty much a nobody. No history of doing this kind of stuff." He also calls the author a "sociopath." Eleven months later, in a federal courtroom, he would say the opposite under oath.
ACT IV — THE PLEA AND THE CONSULTANCY (2017–2018)
The denial doesn't survive contact with the FBI. What follows is the softest landing in the story: no prison, and a second career catching the next Anna-Senpai.
-
DEC 2017
Three guilty pleas, unsealed
The Justice Department unseals guilty pleas by Jha, White, and Norman in the District of Alaska: all three to a click-fraud conspiracy that used Mirai-infected devices to fake ad traffic; Jha and White also to the conspiracy to build and run Mirai. Jha pleads guilty separately in the District of New Jersey to the Rutgers attacks under the Computer Fraud and Abuse Act. Prosecutors put the click-fraud take at roughly 200 bitcoin.
-
SEP 2018
No prison — "extraordinary cooperation"
In Alaska the three are sentenced to five years' probation, 2,500 hours of community service each, and $127,000 restitution — and no incarceration. The government's memo credits their "extraordinary cooperation" in identifying other cybercriminals and heading off attacks; prosecutors singled Jha out as "especially helpful, devoting hundreds of hours." The kid who broke the internet spent his sentence working for the people who investigate it.
-
OCT 2018
$8.6M for Rutgers
In New Jersey, Jha draws six months' home confinement, another 2,500 hours of community service, and $8.6 million in restitution to Rutgers for at least four attacks on the school he attended. His attorney noted the judge called Jha's cooperation more valuable than any he'd seen from the bench.
both sides, on the record
The case: Jha co-authored malware that enslaved hundreds of thousands of other people's devices, used it to run a Minecraft protection racket and a click-fraud scheme, and knocked a security journalist, a major host, and a slice of the American internet offline. He then lied about all of it to that journalist's face. These are not allegations — he pleaded guilty to them in two federal districts.
The unmasking held up: Krebs's January 2017 identification, which Jha publicly denied, was confirmed by the guilty pleas eleven months later. The résumé, the anime handle, and the Go code all pointed the same way, and the paperwork agreed.
He didn't set out to break the internet: prosecutors themselves said the point was a video game, not a nation-state attack — the scale was an accident of a tool that outgrew its purpose. He was a college student, not a spy.
He owned it and made it right, sort of: after the denial, Jha cooperated at a level the court called extraordinary — hundreds of hours helping investigators — and took the restitution. The government asked for leniency because he earned it, and the judge agreed.
The talent was real: the same skills that built Mirai now work the other side of the fence. The FBI didn't want him in a cell; it wanted him at a keyboard.
YOU DECIDE
The intrusions were real, the racket was real, the denial was a lie, and he pleaded to all of it. Strip the anime handle and the "I made my money" swagger away and you're left with a gifted kid who treated a game like a market, built something bigger than he could aim, and got the softest possible landing because he was more useful catching the next one than sitting in a cell.
The archive doesn't grade on talent. It keeps the 620 Gbps, the denial, and the guilty plea — in that order.
evidence locker
PRIMARY / COURT & INVESTIGATION
SENTENCING
CONTEXT & FIRST-PARTY
The standard. Paras Jha is a living person who was a young adult at the time of the conduct. Everything asserted as fact here is drawn from his own federal guilty pleas and the sentencing record; the identification of "Anna-Senpai" as Jha originated in Brian Krebs's January 2017 reporting (attributed) and was confirmed by those pleas. Jha's contemporaneous denial is quoted at full strength, as is the cooperation the court credited to him. No operational detail is given beyond the public fact that Mirai spread through devices left on default credentials. Nothing beyond the record is asserted. If a line here couldn't survive scrutiny, it wouldn't be on the page.