Researchers uncover BrickerBot-powered botnet attacks that are designed to brick poorly secured Linux-based routers and other IoT devices
Ongoing “BrickerBot” attacks might be trying to kill devices before they can join a botnet. — Researchers have uncovered a rash of ongoing attacks designed …
Context & Ripple Effects
This story extends a line of coverage going back years: researchers had already documented self-sustaining botnets built on poorly secured routers in 2015, and even malware like Linux.WiFatch that appeared to harden the devices it infected. BrickerBot breaks from both models by permanently destroying the hardware instead of recruiting or protecting it.
The description's framing — killing devices before they can join a botnet — makes BrickerBot a direct attack on the recruitment pool that made those earlier botnets self-sustaining, which is why it matters beyond yet another IoT scare.
First-order effects
- Owners of poorly secured Linux-based routers and IoT devices lose their hardware outright — no cleanup or patch path once a device is bricked.
Second-order effects
- Botnet operators competing for the same vulnerable-device pool lose inventory, pushing them toward either better exploitation tooling or, as later Silex attacks showed, copying the wipe-and-destroy playbook itself.
Third-order effects
- The pattern held long enough to scale: seven years later, malware attributed in Lumen's analysis of 600K+ bricked routers at a US ISP showed destructive IoT attacks moving from vigilante-scale nuisance to mass-casualty events, pointing toward regulatory pressure on default credentials and vendor patching for consumer-connected hardware.
The trend: IoT malware is shifting from silently harvesting insecure devices into botnets toward deliberately destroying them, with each wave raising the cost of shipping unpatchable consumer hardware.