BrickerBot
malware targeting IoT devices

BrickerBot was malware that attempted to permanently destroy ("brick") insecure Internet of Things devices. BrickerBot logged into poorly-secured devices and ran harmful commands to disable them. It was first discovered by Radware after it attacked their honeypot in April 2017. On December 10, 2017, BrickerBot was retired.
The most infected devices were in Argentina, followed by North America and Europe, and Asia (including India).
Discovery
BrickerBot.1 and BrickerBot.2
The BrickerBot family of malware was first discovered by Radware on April 20, 2017, when BrickerBot attacked their honeypot 1,895 times over four days. BrickerBot's method of attack was to brute-force the telnet password, then run commands using BusyBox to corrupt MMC and MTD storage, delete all files, and disconnect the device from the Internet. Less than an hour after the initial attack, bots began sending a slightly different set of malicious commands, indicating a new version, BrickerBot.2. BrickerBot.2 used the Tor network to hide its location, did not rely on the presence of busybox on the target, and was able to corrupt more types of storage devices.
BrickerBot.3 and BrickerBot.4
BrickerBot.3 was detected on May 20, 2017, one month after the initial discovery of BrickerBot.1.
The public source identifies “BrickerBot” as malware targeting IoT devices. This brief keeps that definition visible, then builds a research path around BrickerBot, malware and targeting.
Why this record matters
A short description can identify a subject without explaining its stakes. For “BrickerBot”, the useful work is to connect “malware targeting IoT devices” to the records capable of establishing context and consequence.
Named sources, stable identifiers and responsible institutions provide the strongest route from overview to verifiable evidence. The source revision retrieved here is dated Mar 27, 2026. The linked authority identifier is Q60740739. None of the 0 selected statements returned an explicit reference. The first chronological checks are 2017.
A concise general-reference account can conceal disagreements about scope, terminology or the weight assigned to individual sources. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “BrickerBot”, its source revision and the description used here.
- Expand the search: follow BrickerBot primary sources, BrickerBot archive and BrickerBot research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “BrickerBot”?
- What terminology or title could unlock a more precise catalogue search?
- Which institution is responsible for the underlying evidence?
Search terms from this dossier
This entry incorporates text from “BrickerBot” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.