New Silex malware has begun bricking several hundred poorly secured IoT devices per hour, using default credentials to log in and then wipe devices
Context & Ripple Effects
Destructive IoT malware has a short but distinct lineage in this coverage: researchers first documented BrickerBot-powered botnets bricking poorly secured routers back in 2017, after the curious Linux.WiFatch malware that appeared to secure infected systems showed how much of the internet's device fleet sits exposed on default settings.
Silex revives that playbook at scale — logging in with factory credentials and wiping firmware outright rather than recruiting devices into a botnet — and it lands just as malware was found to have bricked 600K+ routers tied to a US ISP's autonomous system, confirming that permanent destruction of consumer-grade network gear is now a recurring attack class, not a one-off.
First-order effects
- Owners of the affected devices lose them permanently — a wipe is unrecoverable without physical reflashing — and anyone still running default credentials on internet-facing IoT gear is an active target at a rate of hundreds of bricks per hour.
Second-order effects
- The attacks push device makers and ISPs toward forced credential rotation, mandatory password setup at first boot, and remote remediation programs of the kind implied by the large-scale router-bricking incident attributed to a US ISP.
Third-order effects
- If destructive campaigns keep outpacing patch cycles, liability for insecure defaults shifts from users to manufacturers and carriers, accelerating regulation of baseline IoT security and consolidation around vendors who ship locked-down firmware.
The trend: IoT malware is shifting from hijacking devices for botnets to destroying them outright, making unpatched default-credential devices an expendable casualty class.