Silex is a destructive IoT malware family designed to brick poorly secured internet-connected devices. It is associated with the actor known as Light The Sylveon, also referred to as Light The Leafon, and was reportedly developed with two collaborators. Silex gained notoriety for compromising vulnerable devices at scale and rendering them inoperable through destructive shell commands rather than monetizing access through conventional botnet activity.
Silex typically gains access to exposed IoT systems over Telnet by using weak or default credentials. After access is obtained, it verifies the target environment and executes a sequence of destructive actions intended to disable recovery through normal administration. Observed behavior includes enumerating storage partitions, overwriting storage with random data, deleting network configuration, flushing firewall rules, inserting rules that block connectivity, and rebooting or halting the device. These actions can leave devices effectively bricked, although recovery may be possible in some cases through firmware reinstallation.
The malware has been observed in ARM binaries and also in a Bash-based form, indicating support for Linux and other Unix-like embedded environments beyond a single processor architecture. Its tradecraft reflects the common attack surface of consumer and small-office IoT devices that expose remote administration services and retain insecure default credentials.
Silex is notable within the IoT threat landscape as a bricker or wiper rather than a conventional DDoS-focused botnet payload. It has also influenced later malware development: destructive routines attributed to Silex have been identified in newer IoT botnet codebases under development. The malware is frequently compared with BrickerBot because both families intentionally destroy vulnerable IoT devices instead of preserving them for long-term botnet use.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
What Is Wiper Malware? Wipers are malware that delete data on a device or make it inaccessible. They can be used for sabotage, to destroy evidence of an attack or simply to make a device unusable.
IoT wipers often rewrite important parts of the firmware of an IoT device, rendering that device useless, so they are also known as 'brickers'.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An IoT wiper described here as a BrickerBot variant associated with low-barrier destructive bricking activity.
IoT wiper whose code appears reused in Kaden botnet; previously demonstrated destructive wiping of IoT devices.
SILEX is destructive IoT malware intended to render vulnerable devices inoperable by issuing destructive commands.
Destructive IoT malware that compromises poorly protected devices over Telnet using weak or default credentials, then bricks them by overwriting storage/flash partitions with random data, deleting network configuration, flushing iptables, dropping connections, and rebooting the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.