BrickerBot is a destructive IoT malware family designed to cause permanent denial of service by rendering vulnerable internet-connected devices inoperable. Active in 2017 and associated with the self-described “Internet Chemotherapy” campaign, it targeted poorly secured embedded Linux and BusyBox-based systems, including IoT and some network devices, by abusing exposed remote administration services and weak, default, or hard-coded credentials. Public reporting and government alerting identified multiple variants, notably BrickerBot.1 and BrickerBot.2, with later sightings of BrickerBot.3 and a rarely observed BrickerBot.4.
After gaining access, BrickerBot executed destructive command sequences intended to corrupt storage, delete files, disrupt networking, and otherwise prevent recovery. Observed behaviors included brute-forcing Telnet access, abusing exposed SSH, invoking BusyBox utilities, corrupting flash and block storage, removing data, and severing connectivity. BrickerBot.2 expanded target coverage beyond systems dependent on BusyBox and used Tor to obscure attack origin. The malware is widely regarded as one of the earliest known IoT wipers or “brickers,” and has been cited as a formative example of destructive tradecraft against embedded devices.
BrickerBot has been linked in open reporting to the persona Janit0r, also referred to as Dr. Cyborkian or The Doctor, who claimed the campaign’s purpose was to disable insecure devices before they could be conscripted into botnets such as Mirai. That claimed vigilante rationale does not change the fact that the malware performed unauthorized destructive actions against third-party systems. US government alerting warned that the malware exploited hard-coded passwords and exposed management services on internet-facing IoT devices, and noted particular impact on outdated embedded and network-device deployments.
BrickerBot is significant in the evolution of IoT threats because it demonstrated that large-scale embedded malware could pursue destruction rather than monetization or botnet growth. It has since been referenced alongside later destructive IoT malware such as Silex and in broader discussions of wiper capabilities affecting embedded, OT-adjacent, and critical-infrastructure environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Dr Cyborkian a.k.a. janit0r did confess in an anonymous post that it was a rather difficult step to sabotage other people’s equipment just to prove his point. But he then goes on to say that the colossally dangerous CVE-2016-10372 situation ultimately left him with no other choice but to go head on with to the threats encountered by the Mirai Botnet. | BrickerBot Malware Used to Sabotage IoT Devices The author of project ‘Internet Chemotherapy’ was able to run such a huge operation with the help of the BrickerBot Malware. This strain of malware was purposely created and deployed to disable poorly protected IoT devices on a biblical scale.
APEP also spreads by taking advantage of CVE-2017-17215, which involves another RCE vulnerability and affects Huawei HG532 router devices, for its attacks. The vulnerability was also reported to be involved in Satori and Brickerbot variants. Huawei has since released a security notice and outlined measures to circumvent possible exploitation. | The vulnerability was also reported to be involved in Satori and Brickerbot variants.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
What Is Wiper Malware? Wipers are malware that delete data on a device or make it inaccessible. They can be used for sabotage, to destroy evidence of an attack or simply to make a device unusable.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware created to permanently disable or sabotage poorly secured IoT devices, effectively rendering infected hardware dysfunctional in order to prevent later compromise.
A destructive IoT malware family that bricked devices by writing random data to block devices, reportedly to prevent their enlistment into Mirai.
Referenced as the source of PLC default credentials later reused by Aisuru samples.
Early IoT wiper/bricker that renders devices unusable.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.